SUSE Container Update Advisory: bci/openjdk
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:387-1
Container Tags        : bci/openjdk:17 , bci/openjdk:17-12.18 , bci/openjdk:latest
Container Release     : 12.18
Severity              : important
Type                  : security
References            : 1205916 1207246 1207248 1208138 CVE-2023-0767 CVE-2023-21835
                        CVE-2023-21843 
-----------------------------------------------------------------

The container bci/openjdk was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:434-1
Released:    Thu Feb 16 09:08:05 2023
Summary:     Security update for mozilla-nss
Type:        security
Severity:    important
References:  1208138,CVE-2023-0767
This update for mozilla-nss fixes the following issues:

  Updated to NSS 3.79.4 (bsc#1208138):

  - CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:435-1
Released:    Thu Feb 16 11:06:29 2023
Summary:     Security update for java-17-openjdk
Type:        security
Severity:    moderate
References:  1205916,1207246,1207248,CVE-2023-21835,CVE-2023-21843
This update for java-17-openjdk fixes the following issues:

  Updated to version jdk-17.0.6.0+10:

  - CVE-2023-21835: Fixed handshake DoS attack against DTLS connections (bsc#1207246).
  - CVE-2023-21843: Fixed soundbank URL remote loading (bsc#1207248).

  Bugfixes:

  - Avoid calling C_GetInfo() too early, before cryptoki is initialized (bsc#1205916).



The following package changes have been done:

- libfreebl3-3.79.4-150400.3.26.1 updated
- libfreebl3-hmac-3.79.4-150400.3.26.1 updated
- mozilla-nss-certs-3.79.4-150400.3.26.1 updated
- libsoftokn3-3.79.4-150400.3.26.1 updated
- mozilla-nss-3.79.4-150400.3.26.1 updated
- libsoftokn3-hmac-3.79.4-150400.3.26.1 updated
- java-17-openjdk-headless-17.0.6.0-150400.3.12.1 updated
- java-17-openjdk-17.0.6.0-150400.3.12.1 updated

SUSE: 2023:387-1 bci/openjdk Security Update

February 17, 2023
The container bci/openjdk was updated

Summary

Advisory ID: SUSE-SU-2023:434-1 Released: Thu Feb 16 09:08:05 2023 Summary: Security update for mozilla-nss Type: security Severity: important Advisory ID: SUSE-SU-2023:435-1 Released: Thu Feb 16 11:06:29 2023 Summary: Security update for java-17-openjdk Type: security Severity: moderate

References

References : 1205916 1207246 1207248 1208138 CVE-2023-0767 CVE-2023-21835

CVE-2023-21843

1208138,CVE-2023-0767

This update for mozilla-nss fixes the following issues:

Updated to NSS 3.79.4 (bsc#1208138):

- CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types.

1205916,1207246,1207248,CVE-2023-21835,CVE-2023-21843

This update for java-17-openjdk fixes the following issues:

Updated to version jdk-17.0.6.0+10:

- CVE-2023-21835: Fixed handshake DoS attack against DTLS connections (bsc#1207246).

- CVE-2023-21843: Fixed soundbank URL remote loading (bsc#1207248).

Bugfixes:

- Avoid calling C_GetInfo() too early, before cryptoki is initialized (bsc#1205916).

The following package changes have been done:

- libfreebl3-3.79.4-150400.3.26.1 updated

- libfreebl3-hmac-3.79.4-150400.3.26.1 updated

- mozilla-nss-certs-3.79.4-150400.3.26.1 updated

- libsoftokn3-3.79.4-150400.3.26.1 updated

- mozilla-nss-3.79.4-150400.3.26.1 updated

- libsoftokn3-hmac-3.79.4-150400.3.26.1 updated

- java-17-openjdk-headless-17.0.6.0-150400.3.12.1 updated

- java-17-openjdk-17.0.6.0-150400.3.12.1 updated

Severity
Container Advisory ID : SUSE-CU-2023:387-1
Container Tags : bci/openjdk:17 , bci/openjdk:17-12.18 , bci/openjdk:latest
Container Release : 12.18
Severity : important
Type : security

Related News