Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
89

Fedora 40: sat4j High Type Confusion CVE-2024-1938, CVE-2024-1939 Advisory

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : sat4j Product : Fedora 40 Version : 2.3.5 Release : 30.fc40 URL : http://www.sat4j.org/ Summary : A library of SAT solvers written in Java Description : The aim of the SAT4J library is to provide an efficient library of SAT solvers in Java. The SAT4J library targets first users of SAT "black boxes", those willing to embed SAT technologies into their application without worrying about the details. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 2.3.5-30 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Critical vulnerability patch released for sat4j in Fedora 40 targeting type confusion flaws in Java. Prompt intervention advised.. Fedora 40 Security, Java 21 Update, Type Confusion Fix, sat4j Advisory. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2024 Fedora
89

Fedora 40: FEDORA-2024-129d8ca6fc High: Batik Type Confusion Issues

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : batik Product : Fedora 40 Version : 1.14 Release : 13.fc40 URL : https://xmlgraphics.apache.org/batik/ Summary : Scalable Vector Graphics for Java Description : Batik is a Java(tm) technology based toolkit for applications that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 1.14-13 - Rebuilt for java-21-openjdk as system jdk * Tue Feb 27 2024 Jiri Vanek - 1.14-12 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: typeconfusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest Fedora 40 release for Batik resolves crucial type mismatch problems and fixes several glitches found in Java 21.. Fedora Security, Batik Type Confusion, Java 21 Fix. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2024 Fedora
199

CentOS 6: CESA-2020-1508 Important: java-1.7.0-openjdk Security Fix

Upstream details at : https://access.redhat.com/errata/RHSA-2020:1508. CentOS Errata and Security Advisory 2020:1508 Important Upstream details at : https://access.redhat.com/errata/RHSA-2020:1508 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: 26e47d9aa242a8ff26a922cd6158f57919148a340d3a4a45eac954c6eae93f58 java-1.7.0-openjdk-1.7.0.261-2.6.22.1.el6_10.i686.rpm 350776ba966fcf4e4d56f7eaf34d49dc095a4cb26328ee474a26d02dd7688232 java-1.7.0-openjdk-demo-1.7.0.261-2.6.22.1.el6_10.i686.rpm 839da6b4f494a67b660bcf50e75b6c10113aec243207becd76bb15373d551290 java-1.7.0-openjdk-devel-1.7.0.261-2.6.22.1.el6_10.i686.rpm 99b50e96607dcb1da179ac9a25f2d5f1271bfe9aab9fe00c669b5a5a9c4a4a21 java-1.7.0-openjdk-javadoc-1.7.0.261-2.6.22.1.el6_10.noarch.rpm d70ec50fdef1d55ee0e053d28923c54d48700036699f66ebadca036fa996deda java-1.7.0-openjdk-src-1.7.0.261-2.6.22.1.el6_10.i686.rpm x86_64: dcaadaedd419044b567051754bda337448c76939fbb6511d2b9c080a4ce419fe java-1.7.0-openjdk-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm d2271d2bd3c586871b777f3fe63b62744b80bb1620a213f0c8b05f4d3c5b07b3 java-1.7.0-openjdk-demo-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm 043079714593561b7636db4712a2d9e0906ed8bf3ae4abc09b77175c28836db8 java-1.7.0-openjdk-devel-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm 99b50e96607dcb1da179ac9a25f2d5f1271bfe9aab9fe00c669b5a5a9c4a4a21 java-1.7.0-openjdk-javadoc-1.7.0.261-2.6.22.1.el6_10.noarch.rpm aa768ae41a5f835d30b6773ae0f89e3a0e00c053e69615aaec957ae8e250381c java-1.7.0-openjdk-src-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm Source: 7203176340c185894bab2ab36905072a5fa5e0f03462179066e7665c54a38df1 java-1.7.0-openjdk-1.7.0.261-2.6.22.1.el6_10.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical CentOS 6 notification pertains to java-1.7.0-openjdk remedies and revisionsaddressing vulnerabilities. Immediate attention required for safeguarding systems.. CentOS Update, Java Security, Security Advisory, Linux Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 27, 2020 Important CentOS
100

SUSE: 2020:0024-1 Moderate: java-1_8_0-ibm Fix for Multiple Issues

An update that fixes 16 vulnerabilities is now available. . SUSE Security Update: Security update for java-1_8_0-ibm ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0024-1 Rating: moderate References: #1154212 #1158442 Cross-References: CVE-2019-17631 CVE-2019-2933 CVE-2019-2945 CVE-2019-2958 CVE-2019-2962 CVE-2019-2964 CVE-2019-2973 CVE-2019-2975 CVE-2019-2978 CVE-2019-2981 CVE-2019-2983 CVE-2019-2988 CVE-2019-2989 CVE-2019-2992 CVE-2019-2996 CVE-2019-2999 Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Enterprise Storage 5 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes 16 vulnerabilities is now available. Description: This update for java-1_8_0-ibm fixes the following issues: - Update to Java 8.0 Service Refresh 6 [bsc#1158442, bsc#1154212] * Security fixes: CVE-2019-2933 CVE-2019-2945 CVE-2019-2958 CVE-2019-2962 CVE-2019-2964CVE-2019-2975 CVE-2019-2978 CVE-2019-2983 CVE-2019-2988 CVE-2019-2989 CVE-2019-2992 CVE-2019-2996 CVE-2019-2999 CVE-2019-2973 CVE-2019-2981 CVE-2019-17631 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-24=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-24=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-24=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-24=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2020-24=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-24=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-24=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2020-24=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-24=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2020-24=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2020-24=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2020-24=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-24=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2020-24=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2020-24=1 - SUSE Enterprise Storage 5: zypper in -t patchSUSE-Storage-5-2020-24=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2020-24=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE OpenStack Cloud 8 (x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE OpenStack Cloud 7 (s390x x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-devel-1.8.0_sr6.0-30.60.1 - SUSE OpenStack Cloud 7 (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (ppc64le s390x x86_64): java-1_8_0-ibm-devel-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (ppc64le s390x x86_64): java-1_8_0-ibm-devel-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-devel-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-devel-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP5 (ppc64le s390x x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP5 (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP4 (ppc64le s390x x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP4 (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (ppc64le s390x x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-devel-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-devel-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-devel-1.8.0_sr6.0-30.60.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - SUSE Enterprise Storage 5 (x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 - HPE Helion Openstack 8 (x86_64): java-1_8_0-ibm-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-alsa-1.8.0_sr6.0-30.60.1 java-1_8_0-ibm-plugin-1.8.0_sr6.0-30.60.1 References: https://www.suse.com/security/cve/CVE-2019-17631.html https://www.suse.com/security/cve/CVE-2019-2933.html https://www.suse.com/security/cve/CVE-2019-2945.html https://www.suse.com/security/cve/CVE-2019-2958.html https://www.suse.com/security/cve/CVE-2019-2962.html https://www.suse.com/security/cve/CVE-2019-2964.html https://www.suse.com/security/cve/CVE-2019-2973.html https://www.suse.com/security/cve/CVE-2019-2975.html https://www.suse.com/security/cve/CVE-2019-2978.html https://www.suse.com/security/cve/CVE-2019-2981.html https://www.suse.com/security/cve/CVE-2019-2983.html https://www.suse.com/security/cve/CVE-2019-2988.html https://www.suse.com/security/cve/CVE-2019-2989.html https://www.suse.com/security/cve/CVE-2019-2992.html https://www.suse.com/security/cve/CVE-2019-2996.html https://www.suse.com/security/cve/CVE-2019-2999.html https://bugzilla.suse.com/1154212 https://bugzilla.suse.com/1158442 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Patch for python-3-abc addresses numerous vulnerabilities with 12 corrections and a moderate severity classification.. SUSE Security Update, java-1_8_0-ibm, OpenStack, update, fixes. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jan 07, 2020 Medium SuSE
202

openSUSE Leap 42.3: 2019:0042-1 Important: Java Security Issues Fix

An update that fixes 13 vulnerabilities is now available. . openSUSE Security Update: Security update for java-1_7_0-openjdk ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:0042-1 Rating: important References: #1101644 #1101645 #1101651 #1101656 #1112142 #1112143 #1112144 #1112146 #1112147 #1112152 #1112153 Cross-References: CVE-2018-13785 CVE-2018-16435 CVE-2018-2938 CVE-2018-2940 CVE-2018-2952 CVE-2018-2973 CVE-2018-3136 CVE-2018-3139 CVE-2018-3149 CVE-2018-3169 CVE-2018-3180 CVE-2018-3214 CVE-2018-3639 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. Description: This update for java-1_7_0-openjdk to version 7u201 fixes the following issues: Security issues fixed: - CVE-2018-3136: Manifest better support (bsc#1112142) - CVE-2018-3139: Better HTTP Redirection (bsc#1112143) - CVE-2018-3149: Enhance JNDI lookups (bsc#1112144) - CVE-2018-3169: Improve field accesses (bsc#1112146) - CVE-2018-3180: Improve TLS connections stability (bsc#1112147) - CVE-2018-3214: Better RIFF reading support (bsc#1112152) - CVE-2018-13785: Upgrade JDK 8u to libpng 1.6.35 (bsc#1112153) - CVE-2018-16435: heap-based buffer overflow in SetData function in cmsIT8LoadFromFile - CVE-2018-2938: Support Derby connections (bsc#1101644) - CVE-2018-2940: Better stack walking (bsc#1101645) - CVE-2018-2952: Exception to Pattern Syntax (bsc#1101651) - CVE-2018-2973: Improve LDAP support (bsc#1101656) - CVE-2018-3639 cpu speculative store bypass mitigation This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSESecurity Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-42=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): java-1_7_0-openjdk-1.7.0.201-54.1 java-1_7_0-openjdk-accessibility-1.7.0.201-54.1 java-1_7_0-openjdk-bootstrap-1.7.0.201-54.1 java-1_7_0-openjdk-bootstrap-debuginfo-1.7.0.201-54.1 java-1_7_0-openjdk-bootstrap-debugsource-1.7.0.201-54.1 java-1_7_0-openjdk-bootstrap-devel-1.7.0.201-54.1 java-1_7_0-openjdk-bootstrap-devel-debuginfo-1.7.0.201-54.1 java-1_7_0-openjdk-bootstrap-headless-1.7.0.201-54.1 java-1_7_0-openjdk-bootstrap-headless-debuginfo-1.7.0.201-54.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-54.1 java-1_7_0-openjdk-debugsource-1.7.0.201-54.1 java-1_7_0-openjdk-demo-1.7.0.201-54.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-54.1 java-1_7_0-openjdk-devel-1.7.0.201-54.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-54.1 java-1_7_0-openjdk-headless-1.7.0.201-54.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-54.1 java-1_7_0-openjdk-src-1.7.0.201-54.1 - openSUSE Leap 42.3 (noarch): java-1_7_0-openjdk-javadoc-1.7.0.201-54.1 References: https://www.suse.com/security/cve/CVE-2018-13785.html https://www.suse.com/security/cve/CVE-2018-16435.html https://www.suse.com/security/cve/CVE-2018-2938.html https://www.suse.com/security/cve/CVE-2018-2940.html https://www.suse.com/security/cve/CVE-2018-2952.html https://www.suse.com/security/cve/CVE-2018-2973.html https://www.suse.com/security/cve/CVE-2018-3136.html https://www.suse.com/security/cve/CVE-2018-3139.html https://www.suse.com/security/cve/CVE-2018-3149.html https://www.suse.com/security/cve/CVE-2018-3169.html https://www.suse.com/security/cve/CVE-2018-3180.html https://www.suse.com/security/cve/CVE-2018-3214.html https://www.suse.com/security/cve/CVE-2018-3639.html https://bugzilla.suse.com/1101644 https://bugzilla.suse.com/1101645 https://bugzilla.suse.com/1101651 https://bugzilla.suse.com/1101656 https://bugzilla.suse.com/1112142 https://bugzilla.suse.com/show_bug.cgi?id=1112143 https://bugzilla.suse.com/1112144 https://bugzilla.suse.com/1112146 https://bugzilla.suse.com/1112147 https://bugzilla.suse.com/1112152 https://bugzilla.suse.com/show_bug.cgi?id=1112153 -- . A crucial security patch for java-1_7_0-openjdk addresses 13 vulnerabilities in openSUSE. Discover the main enhancements.. openSUSE Security Update, Java Issues Fix, Patch Instructions, Important Fixes, JDK Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 12, 2019 Important OpenSUSE
100

SUSE: 2016:3068-1 Crucial Java Update Addresses Six Critical Issues

An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.. SUSE Security Update: Security update for java-1_7_0-ibm ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:3068-1 Rating: important References: #1009280 #992537 Cross-References: CVE-2016-5542 CVE-2016-5554 CVE-2016-5556 CVE-2016-5568 CVE-2016-5573 CVE-2016-5597 Affected Products: SUSE OpenStack Cloud 5 SUSE Manager Proxy 2.1 SUSE Manager 2.1 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Server 11-SP2-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for java-1_7_0-ibm fixes the following issues: - Version update to 7.0-9.60 (bsc#1009280, bsc#992537) fixing the following CVE's: CVE-2016-5568, CVE-2016-5556, CVE-2016-5573, CVE-2016-5597, CVE-2016-5554, CVE-2016-5542 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 5: zypper in -t patch sleclo50sp3-java-1_7_0-ibm-12879=1 - SUSE Manager Proxy 2.1: zypper in -t patch slemap21-java-1_7_0-ibm-12879=1 - SUSE Manager 2.1: zypper in -t patch sleman21-java-1_7_0-ibm-12879=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-java-1_7_0-ibm-12879=1 - SUSE Linux Enterprise Server 11-SP2-LTSS: zypper in -t patch slessp2-java-1_7_0-ibm-12879=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-java-1_7_0-ibm-12879=1 To bring yoursystem up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 5 (x86_64): java-1_7_0-ibm-1.7.0_sr9.60-58.2 java-1_7_0-ibm-alsa-1.7.0_sr9.60-58.2 java-1_7_0-ibm-devel-1.7.0_sr9.60-58.2 java-1_7_0-ibm-jdbc-1.7.0_sr9.60-58.2 java-1_7_0-ibm-plugin-1.7.0_sr9.60-58.2 - SUSE Manager Proxy 2.1 (x86_64): java-1_7_0-ibm-1.7.0_sr9.60-58.2 java-1_7_0-ibm-alsa-1.7.0_sr9.60-58.2 java-1_7_0-ibm-devel-1.7.0_sr9.60-58.2 java-1_7_0-ibm-jdbc-1.7.0_sr9.60-58.2 java-1_7_0-ibm-plugin-1.7.0_sr9.60-58.2 - SUSE Manager 2.1 (s390x x86_64): java-1_7_0-ibm-1.7.0_sr9.60-58.2 java-1_7_0-ibm-devel-1.7.0_sr9.60-58.2 java-1_7_0-ibm-jdbc-1.7.0_sr9.60-58.2 - SUSE Manager 2.1 (x86_64): java-1_7_0-ibm-alsa-1.7.0_sr9.60-58.2 java-1_7_0-ibm-plugin-1.7.0_sr9.60-58.2 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): java-1_7_0-ibm-1.7.0_sr9.60-58.2 java-1_7_0-ibm-devel-1.7.0_sr9.60-58.2 java-1_7_0-ibm-jdbc-1.7.0_sr9.60-58.2 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 x86_64): java-1_7_0-ibm-alsa-1.7.0_sr9.60-58.2 java-1_7_0-ibm-plugin-1.7.0_sr9.60-58.2 - SUSE Linux Enterprise Server 11-SP2-LTSS (i586 s390x x86_64): java-1_7_0-ibm-1.7.0_sr9.60-58.2 java-1_7_0-ibm-devel-1.7.0_sr9.60-58.2 java-1_7_0-ibm-jdbc-1.7.0_sr9.60-58.2 - SUSE Linux Enterprise Server 11-SP2-LTSS (i586 x86_64): java-1_7_0-ibm-alsa-1.7.0_sr9.60-58.2 java-1_7_0-ibm-plugin-1.7.0_sr9.60-58.2 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): java-1_7_0-ibm-1.7.0_sr9.60-58.2 java-1_7_0-ibm-alsa-1.7.0_sr9.60-58.2 java-1_7_0-ibm-devel-1.7.0_sr9.60-58.2 java-1_7_0-ibm-jdbc-1.7.0_sr9.60-58.2 java-1_7_0-ibm-plugin-1.7.0_sr9.60-58.2 References: https://www.suse.com/security/cve/CVE-2016-5542.html https://www.suse.com/security/cve/CVE-2016-5554.html https://www.suse.com/security/cve/CVE-2016-5556.html https://www.suse.com/security/cve/CVE-2016-5568.html https://www.suse.com/security/cve/CVE-2016-5573.html https://www.suse.com/security/cve/CVE-2016-5597.html https://bugzilla.suse.com/1009280 https://bugzilla.suse.com/992537 . SUSE Security Patch introduces essential resolutions for python-3_8_0 vulnerabilities, safeguarding system reliability and safety.. SUSE Security Update, Java Fix, System Update, Software Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 09, 2016 Important SuSE
100

SUSE: 2021:1042-1 Critical: Python-3_8_1-Security Update

An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.. SUSE Security Update: Security update for java-1_7_1-ibm ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:3041-1 Rating: important References: #1009280 Cross-References: CVE-2016-5542 CVE-2016-5554 CVE-2016-5556 CVE-2016-5568 CVE-2016-5573 CVE-2016-5597 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for java-1_7_1-ibm fixes the following issues: - Version update to 7.1-3.60 (bsc#1009280) fixing the following CVE's: CVE-2016-5568, CVE-2016-5556, CVE-2016-5573, CVE-2016-5597, CVE-2016-5554, CVE-2016-5542 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-java-1_7_1-ibm-12873=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-java-1_7_1-ibm-12873=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ppc64 s390x x86_64): java-1_7_1-ibm-devel-1.7.1_sr3.60-19.2 - SUSE Linux Enterprise Server 11-SP4 (i586 ppc64 s390x x86_64): java-1_7_1-ibm-1.7.1_sr3.60-19.2 java-1_7_1-ibm-jdbc-1.7.1_sr3.60-19.2 - SUSE Linux Enterprise Server 11-SP4 (i586 x86_64): java-1_7_1-ibm-alsa-1.7.1_sr3.60-19.2 java-1_7_1-ibm-plugin-1.7.1_sr3.60-19.2 References: https://www.suse.com/security/cve/CVE-2016-5542.html https://www.suse.com/security/cve/CVE-2016-5554.html https://www.suse.com/security/cve/CVE-2016-5556.html https://www.suse.com/security/cve/CVE-2016-5568.html https://www.suse.com/security/cve/CVE-2016-5573.html https://www.suse.com/security/cve/CVE-2016-5597.html https://bugzilla.suse.com/1009280 . Crucial SUSE release for java-1_7_1-ibm addresses 6 major security flaws swiftly. Review specifics for setup.. SUSE Security Update, Java Fix, Software Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 07, 2016 Important SuSE
87

Debian: DSA-3403-1 Moderate: Libcommons-Collections3-Java Deserialization

This update backports changes from the commons-collections 3.2.2 release which disable the deserialisation of the functors classes unless the system property org.apache.commons.collections.enableUnsafeSerialization is set to 'true'. This fixes a vulnerability in unsafe applications . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3403-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff November 24, 2015 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libcommons-collections3-java This update backports changes from the commons-collections 3.2.2 release which disable the deserialisation of the functors classes unless the system property org.apache.commons.collections.enableUnsafeSerialization is set to 'true'. This fixes a vulnerability in unsafe applications deserialising objects from untrusted sources without sanitising the input data. Classes considered unsafe are: CloneTransformer, ForClosure, InstantiateFactory, InstantiateTransformer, InvokerTransformer, PrototypeCloneFactory, PrototypeSerializationFactory and WhileClosure. For the oldstable distribution (wheezy), this problem has been fixed in version 3.2.1-5+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 3.2.1-7+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 3.2.2-1. For the unstable distribution (sid), this problem has been fixed in version 3.2.2-1. We recommend that you upgrade your libcommons-collections3-java packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Addresses a deserialization security flaw inlibcommons-collections3-java caused by improper handling of objects; update advised.. libcommons-collections3-java, deserialization, Debian updates. . LinuxSecurity.com Team

Calendar%202 Nov 24, 2015 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200