Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2020:3191-1 Important: Java-1_8_0-OpenJDK Security Update

suse
Calendar Grey November 5, 2020
Dist Suse Esm H88
This Arch Linux security patch resolves 12 vulnerabilities in python-3.9. Necessary for safeguarding system reliability.
An update that fixes 16 vulnerabilities is now available

Summary

This update for java-1_8_0-openjdk fixes the following issues: - Fix regression "8250861: Crash in MinINode::Ideal(PhaseGVN*, bool)", introduced in October 2020 CPU. - Update to version jdk8u272 (icedtea 3.17.0) (July 2020 CPU, bsc#1174157, and October 2020 CPU, bsc#1177943) * New features + JDK-8245468: Add TLSv1.3 implementation classes from 11.0.7 + PR3796: Allow the number of curves supported to be specified * Security fixes + JDK-8028431, CVE-2020-14579: NullPointerException in DerValue.equals(DerValue) + JDK-8028591, CVE-2020-14578: NegativeArraySizeException in sun.security.util.DerInputStream.getUnalignedBitString() + JDK-8230613: Better ASCII conversions + JDK-8231800: Better listing of arrays + JDK-8232014: Expand DTD support + JDK-8233255: Better Swing Buttons

References

#1171352 #1174157 #1177943

Cross- CVE-2020-14556 CVE-2020-14577 CVE-2020-14578

CVE-2020-14579 CVE-2020-14581 CVE-2020-14583

CVE-2020-14593 CVE-2020-14621 CVE-2020-14779

CVE-2020-14781 CVE-2020-14782 CVE-2020-14792

CVE-2020-14796 CVE-2020-14797 CVE-2020-14798

CVE-2020-14803

Affected Products:

SUSE OpenStack Cloud Crowbar 9

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 9

SUSE OpenStack Cloud 8

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP4

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP5

SUSE Linux Enterprise Server 12-SP4-LTSS

SUSE Linux Enterprise Server 12-SP3-LTSS

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3191-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here