Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 12 articles for you...
217

Oracle Linux 7: ELSA-2024-4560 Important Java Security Patch

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4560 http://linux.oracle.com/errata/ELSA-2024-4560.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: java-1.8.0-openjdk-1.8.0.412.b08-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-1.8.0.412.b08-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.412.b08-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-accessibility-1.8.0.412.b08-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.412.b08-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-demo-1.8.0.412.b08-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.412.b08-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-devel-1.8.0.412.b08-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.412.b08-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-headless-1.8.0.412.b08-1.0.1.el7_9.x86_64.rpm java-1.8.0-openjdk-javadoc-1.8.0.412.b08-1.0.1.el7_9.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.412.b08-1.0.1.el7_9.noarch.rpm java-1.8.0-openjdk-src-1.8.0.412.b08-1.0.1.el7_9.i686.rpm java-1.8.0-openjdk-src-1.8.0.412.b08-1.0.1.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//java-1.8.0-openjdk-1.8.0.412.b08-1.0.1.el7_9.src.rpm Related CVEs: CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21144 CVE-2024-21145 CVE-2024-21147 Description of changes: [1:1.8.0.412.b08-1.0.1] - Fixes openjdk below given CVE issues - CVE-2024-21131 Improve-UTF8-String-supports - CVE-2024-21138 Better-symbol-storage - Fixes bad immediate dominator info openjdk bug8262017 - Fixes malformed control flow openjdk bug8303466 - CVE-2024-21140 Improved-loop-handling - CVE-2024-21144 Enhance-Pack-200-loading - CVE-2024-21145 Improve-2D-image-handling - CVE-2024-21147 Improve-array-management _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Update ELSA-2024-4561 outlinescritical enhancements for java-1.8.0-openjdk that tackle multiple vulnerabilities.. Oracle Linux Updates, Java Security Updates, Important Security Fixes, Linux Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 18, 2024 Important Oracle
100

openSUSE: 2022:3092-1 Critical: java-1_8_0-openj9 Security Patch

An update that fixes 9 vulnerabilities is now available. . SUSE Security Update: Security update for java-1_8_0-openj9 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3092-1 Rating: important References: #1198671 #1198672 #1198673 #1198674 #1198675 #1198935 #1201684 #1201692 #1201694 Cross-References: CVE-2021-41041 CVE-2022-21426 CVE-2022-21434 CVE-2022-21443 CVE-2022-21476 CVE-2022-21496 CVE-2022-21540 CVE-2022-21541 CVE-2022-34169 CVSS scores: CVE-2021-41041 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21426 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-21426 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-21434 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21434 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21443 (NVD) : 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-21443 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-21476 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2022-21476 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2022-21496 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21496 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21540 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-21540 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-21541 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-21541 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-34169 (NVD): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-34169 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes 9 vulnerabilities is now available. Description: This update for java-1_8_0-openj9 fixes the following issues: - Updated to OpenJDK 8u345 build 01 with OpenJ9 0.33.0 virtual machine: - CVE-2022-34169: Fixed an integer truncation issue in the Xalan Java XSLT library that occurred when processing malicious stylesheets (bsc#1201684). - CVE-2022-21541: Fixed a potential bypass of sandbox restrictions in the Hotspot component (bsc#1201692). - CVE-2022-21540: Fixed a potential bypass of sandbox restrictions in the Hotspot component (bsc#1201694). - Updated to OpenJDK 8u332 build 09 with OpenJ9 0.32.0 virtual machine: - CVE-2021-41041: Failed an issue that could allow unverified methods to be invoked using MethodHandles (bsc#1198935). - CVE-2022-21426: Fixed a remote partial denial of service issue (component: JAXP) (bsc#1198672). - CVE-2022-21434: Fixed an issue that could allow a remote attacker to update, insert or delete data (component: Libraries) (bsc#1198674). - CVE-2022-21443: Fixed a remote partial denial of service issue (component: Libraries) (bsc#1198675). - CVE-2022-21476: Fixed an issue that could allow unauthorized access to confidential data (component: Libraries) (bsc#1198671). - CVE-2022-21496: Fixed an issue that could allow a remote attacker to update, insert or delete data (component: JNDI) (bsc#1198673). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: -openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3092=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3092=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): java-1_8_0-openj9-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-accessibility-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-debuginfo-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-debugsource-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-demo-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-demo-debuginfo-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-devel-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-devel-debuginfo-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-headless-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-headless-debuginfo-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-src-1.8.0.345-150200.3.24.1 - openSUSE Leap 15.4 (noarch): java-1_8_0-openj9-javadoc-1.8.0.345-150200.3.24.1 - openSUSE Leap 15.3 (ppc64le s390x x86_64): java-1_8_0-openj9-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-accessibility-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-debuginfo-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-debugsource-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-demo-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-demo-debuginfo-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-devel-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-headless-1.8.0.345-150200.3.24.1 java-1_8_0-openj9-src-1.8.0.345-150200.3.24.1 - openSUSE Leap 15.3 (noarch): java-1_8_0-openj9-javadoc-1.8.0.345-150200.3.24.1 References: https://www.suse.com/security/cve/CVE-2021-41041.html https://www.suse.com/security/cve/CVE-2022-21426.html https://www.suse.com/security/cve/CVE-2022-21434.html https://www.suse.com/security/cve/CVE-2022-21443.html https://www.suse.com/security/cve/CVE-2022-21476.html https://www.suse.com/security/cve/CVE-2022-21496.html https://www.suse.com/security/cve/CVE-2022-21540.html https://www.suse.com/security/cve/CVE-2022-21541.html https://www.suse.com/security/cve/CVE-2022-34169.html https://bugzilla.suse.com/1198671 https://bugzilla.suse.com/1198672 https://bugzilla.suse.com/1198673 https://bugzilla.suse.com/1198674 https://bugzilla.suse.com/1198675 https://bugzilla.suse.com/1198935 https://bugzilla.suse.com/1201684 https://bugzilla.suse.com/1201692 https://bugzilla.suse.com/1201694 . Crucial notice regarding java-1_8_0-openj9 resolves various vulnerabilities in SUSE: prompt intervention advised.. Critical Patch, Java Hotspot, OpenJ9 Security, SUSE Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 06, 2022 Important SuSE
199

CentOS 7: CESA-2022-5687 Important: Java 11 OpenJDK Update

Upstream details at : https://access.redhat.com/errata/RHSA-2022:5687. CentOS Errata and Security Advisory 2022:5687 Important Upstream details at : https://access.redhat.com/errata/RHSA-2022:5687 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 839aadc2fbe0a7a4b708e39eb1e3e9359bbbad64641fd674e425f561de5d004a java-11-openjdk-11.0.16.0.8-1.el7_9.i686.rpm e63709673c8670886d3e9e2205785adba63f0186853bcf74298fcce168c18f0d java-11-openjdk-11.0.16.0.8-1.el7_9.x86_64.rpm 4660a5a7faa79cea2990c384533fca3da9b3ac6afdf6f55b36b2cad51352c3e0 java-11-openjdk-demo-11.0.16.0.8-1.el7_9.i686.rpm 6bba16931590ee051b717e6cc7eaf6319e483746bab088b484dada27e5f230d5 java-11-openjdk-demo-11.0.16.0.8-1.el7_9.x86_64.rpm 3e729bea301dda80bd7dad924182af1a8859d3473da42b7cb9ed78adebef8963 java-11-openjdk-devel-11.0.16.0.8-1.el7_9.i686.rpm d91a5237171093f889f2e37c55c5cbf4f02728ff2fb050c08f0547c1c7cf5f63 java-11-openjdk-devel-11.0.16.0.8-1.el7_9.x86_64.rpm 1619875cba8598818f4bb31d4ba22a7d88804cab9b8ed1e66cb4cf18b1b446cb java-11-openjdk-headless-11.0.16.0.8-1.el7_9.i686.rpm 3038e1befe3903f7b2bfb4fb5ed1ee07a0ba36db33ae2aae4ba05e4040d2b65f java-11-openjdk-headless-11.0.16.0.8-1.el7_9.x86_64.rpm 499aafdde42137b651f07de95acdb9b2b0426c0923756ba0bb98c74731260deb java-11-openjdk-javadoc-11.0.16.0.8-1.el7_9.i686.rpm e9370bcf27554400437736d6d3c4091baa10166592baf0f0a1912084c024255d java-11-openjdk-javadoc-11.0.16.0.8-1.el7_9.x86_64.rpm 8127547ec74cf787276b994c2f00085304d697481622d6712560f5c1fde57dd1 java-11-openjdk-javadoc-zip-11.0.16.0.8-1.el7_9.i686.rpm a11deef2840f7fe80ce1b946609ec3aa04069da0557383edb2dd88107312e356 java-11-openjdk-javadoc-zip-11.0.16.0.8-1.el7_9.x86_64.rpm 5ef7809b46025089f784a5c5eef97c5cb1c0ae4576bd7a05f04c657f2231d054 java-11-openjdk-jmods-11.0.16.0.8-1.el7_9.i686.rpm 7d5c7ed2663b8b4d93ccdce3e87fa7b84c42697397d9594170591871b706c60d java-11-openjdk-jmods-11.0.16.0.8-1.el7_9.x86_64.rpm 39b2ee3cdead3a8fa94b2f7fb082014e56dc28992ac2740a46795004ac7dd6c0 java-11-openjdk-src-11.0.16.0.8-1.el7_9.i686.rpm 6cd18c7d7a47f7f1e42e63865172f463162be9c7697c5e7b1953c41099a4d25d java-11-openjdk-src-11.0.16.0.8-1.el7_9.x86_64.rpm 2128f5867b50e91bf6e0f43a02f4d16b03085189d8040f386c115ab75f5a842b java-11-openjdk-static-libs-11.0.16.0.8-1.el7_9.i686.rpm 9dc6103c894580255acdaca6f10c631843d1f93573f2546118ae35826f597314 java-11-openjdk-static-libs-11.0.16.0.8-1.el7_9.x86_64.rpm Source: 2f184d374f33230217eaec88a85599c8f898bb5028cbaee37cc63480709aa168 java-11-openjdk-11.0.16.0.8-1.el7_9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The CentOS 7 notification regarding java-11-openjdk is circulating important update information, featuring necessary patches and crucial security enhancements. Take immediate action.. CentOS Update, Java Security, OpenJDK Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 02, 2022 Important CentOS
217

Oracle Linux 8 ELSA-2022-5696 Critical: Java Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-5696 https://linux.oracle.com/errata/ELSA-2022-5696.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: java-1.8.0-openjdk-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-javadoc-1.8.0.342.b07-2.el8_6.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.342.b07-2.el8_6.noarch.rpm java-1.8.0-openjdk-src-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-demo-fastdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-demo-slowdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-devel-fastdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-devel-slowdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-fastdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-headless-fastdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-headless-slowdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-slowdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-src-fastdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm java-1.8.0-openjdk-src-slowdebug-1.8.0.342.b07-2.el8_6.x86_64.rpm aarch64: java-1.8.0-openjdk-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-accessibility-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-demo-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-devel-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-headless-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-javadoc-1.8.0.342.b07-2.el8_6.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.342.b07-2.el8_6.noarch.rpm java-1.8.0-openjdk-src-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-demo-fastdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-demo-slowdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-devel-fastdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-devel-slowdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-fastdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-headless-fastdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-headless-slowdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-slowdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-src-fastdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm java-1.8.0-openjdk-src-slowdebug-1.8.0.342.b07-2.el8_6.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/java-1.8.0-openjdk-1.8.0.342.b07-2.el8_6.src.rpm Related CVEs: CVE-2022-21540 CVE-2022-21541 CVE-2022-34169 Description of changes: [1:1.8.0.342.b07-1] - Update to shenandoah-jdk8u342-b07 - Update release notes for shenandoah-8u342-b07. - Print release file during build, which should now include a correct SOURCE value from .src-rev - Update tarball script with IcedTea GitHub URL and .src-rev generation - Use "git apply" with patches in the tarball script to allow binary diffs - Remove redundant "REPOS" variable from tarball script - Include script to generate bug list for release notes - Update tzdata requirement to 2022a to match JDK-8283350 - Rebase FIPS patches from fips branch and simplify by using a single patch from that repository - * RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage - * RH2090378: Revert to disabling system security properties and FIPS mode support together - Rebase RH1648249 nss.cfg patch so it applies after the FIPS patch - Perform configuration changes (e.g. nss.cfg, nss.fips.cfg, tzdb.dat) in installjdk - Enable system security properties in the RPM (now disabled by default in the FIPS repo) - Improve security properties test to check both enabled and disabled behaviour - Run security properties test with property debugging on - Explicitly require crypto-policies during build and runtime for system security properties - Resolves:rhbz#2099911 - Resolves: rhbz#2108564 - Resolves: rhbz#2084648 - Resolves: rhbz#2106506 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 receives a significant Java enhancement featuring various security patches. Major upgrades have been implemented.. Oracle Linux Updates, Java Security Fixes, Important Oracle Patch, Linux Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 26, 2022 Critical Oracle
199

CentOS 7: CESA-2022-1487 Critical: Java Vulnerability Fix

Upstream details at : https://access.redhat.com/errata/RHSA-2022:1487. CentOS Errata and Security Advisory 2022:1487 Important Upstream details at : https://access.redhat.com/errata/RHSA-2022:1487 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: ef07f2b266e0d616931d672568f5c39d7789f51adb7332df77df77b19e7882a4 java-1.8.0-openjdk-1.8.0.332.b09-1.el7_9.i686.rpm efd5c472cec8f06ea30eaa8cef287b401fcdf4b0a30e6b2531888ea03f1f9549 java-1.8.0-openjdk-1.8.0.332.b09-1.el7_9.x86_64.rpm 6b024502ff2b69fb4876076ce49575439e5b94cae11c486cd7c59b464106d825 java-1.8.0-openjdk-accessibility-1.8.0.332.b09-1.el7_9.i686.rpm 98887262492c65c2f5769777ce9b0419c04f0f6dbf264e6ea58451ec3eb69bd6 java-1.8.0-openjdk-accessibility-1.8.0.332.b09-1.el7_9.x86_64.rpm 758d2c3a908dc2f48b1ab2c25ec323231a54e2b646281ebbd88192b61617775e java-1.8.0-openjdk-demo-1.8.0.332.b09-1.el7_9.i686.rpm e1931c2c08f74962ec1d742c785c518f1942b86d552b9e27d9cb776d4c555f8a java-1.8.0-openjdk-demo-1.8.0.332.b09-1.el7_9.x86_64.rpm f22ced6e5193aa0b22495fa95e9de588c04f9afa2d6070faf801306fc7e68363 java-1.8.0-openjdk-devel-1.8.0.332.b09-1.el7_9.i686.rpm 8b93611a7e50ab8b817c59d6ef504cf63f14b1ba210b4da69add3f3176898478 java-1.8.0-openjdk-devel-1.8.0.332.b09-1.el7_9.x86_64.rpm d17c2ab42cfa6667afaac7434e92be20fd0330b7a2cf8ad897daec993049f5e9 java-1.8.0-openjdk-headless-1.8.0.332.b09-1.el7_9.i686.rpm 3d985b2d2ec13d506f3e32f82236c706a953bf9178605bd7e9c559e99fe33c06 java-1.8.0-openjdk-headless-1.8.0.332.b09-1.el7_9.x86_64.rpm 029a613293d1ba49b765f0f2ec6fc0b71f6fd43fb1ceff50f43e05dc84f98d20 java-1.8.0-openjdk-javadoc-1.8.0.332.b09-1.el7_9.noarch.rpm 575e728d855d72fba88b860be7518db2c8fa0dc1add9046074dd5d320e1156bb java-1.8.0-openjdk-javadoc-zip-1.8.0.332.b09-1.el7_9.noarch.rpm c2c9b259e70aede7a57ebe7fa8a93a475866d4cce68f6b903edb0875c829bc6c java-1.8.0-openjdk-src-1.8.0.332.b09-1.el7_9.i686.rpm 88bc32f0b32b7bb8891d9dd012f0481bd2103ca60cadb3ebc387b8645c331524 java-1.8.0-openjdk-src-1.8.0.332.b09-1.el7_9.x86_64.rpm Source: f8922920f7e1b952557899bb9486b4a8fcd2d6f0ab614a2581ad55638a0e0ed8 java-1.8.0-openjdk-1.8.0.332.b09-1.el7_9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Stay informed on crucial updates for CentOS 7 and Java by reviewing the security advisory that outlines significant vulnerabilities and essential patches.. CentOS 7 Update, Java Security Patch, Important Java Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 13, 2022 Critical CentOS
100

SUSE: 2021:2798-1 Important Update For Java-1_8_0-Openjdk - Important Fixes

An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for java-1_8_0-openjdk ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2798-1 Rating: important References: #1185056 #1188564 #1188565 #1188566 Cross-References: CVE-2021-2161 CVE-2021-2341 CVE-2021-2369 CVE-2021-2388 CVSS scores: CVE-2021-2161 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2021-2161 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2021-2341 (NVD) : 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVE-2021-2341 (SUSE): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVE-2021-2369 (NVD) : 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVE-2021-2369 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVE-2021-2388 (NVD) : 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-2388 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Module for Legacy Software 15-SP3 SUSE Linux Enterprise Module for Legacy Software 15-SP2 SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: Thisupdate for java-1_8_0-openjdk fixes the following issues: - Update to version jdk8u302 (icedtea 3.20.0) - CVE-2021-2341: Improve file transfers. (bsc#1188564) - CVE-2021-2369: Better jar file validation. (bsc#1188565) - CVE-2021-2388: Enhance compiler validation. (bsc#1188566) - CVE-2021-2161: Less ambiguous processing. (bsc#1185056) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-2798=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-2798=1 - SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-2798=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-2798=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2021-2798=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-2798=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-2798=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2021-2798=1 - SUSE Linux Enterprise Module for Legacy Software 15-SP3: zypper in -t patch SUSE-SLE-Module-Legacy-15-SP3-2021-2798=1 - SUSE Linux Enterprise Module for Legacy Software 15-SP2: zypper in -t patch SUSE-SLE-Module-Legacy-15-SP2-2021-2798=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-2798=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Manager Server 4.0 (ppc64le s390x x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Manager Retail Branch Server 4.0 (x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Manager Proxy 4.0 (x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Linux Enterprise Module for Legacy Software 15-SP3 (aarch64 ppc64le s390x x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Linux Enterprise Module for Legacy Software 15-SP2 (aarch64 ppc64le s390x x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE Enterprise Storage 6 (aarch64 x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 - SUSE CaaS Platform 4.0 (x86_64): java-1_8_0-openjdk-1.8.0.302-3.55.2 java-1_8_0-openjdk-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-debugsource-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-1.8.0.302-3.55.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-1.8.0.302-3.55.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-1.8.0.302-3.55.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.302-3.55.2 References: https://www.suse.com/security/cve/CVE-2021-2161.html https://www.suse.com/security/cve/CVE-2021-2341.html https://www.suse.com/security/cve/CVE-2021-2369.html https://www.suse.com/security/cve/CVE-2021-2388.html https://bugzilla.suse.com/1185056 https://bugzilla.suse.com/1188564 https://bugzilla.suse.com/1188565 https://bugzilla.suse.com/1188566 . SUSE issues a critical security notice for python-3_8_5 addressing significant flaws and enhancements.. Java Security Update, SUSE Package Fixes, OpenJDK Threat Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 20, 2021 Important SuSE
202

openSUSE: 2019:0043-1 Important Patch For openJDK Buffer Overflow

An update that fixes 9 vulnerabilities is now available.. openSUSE Security Update: Security update for java-1_8_0-openjdk ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:0043-1 Rating: important References: #1112142 #1112143 #1112144 #1112146 #1112147 #1112148 #1112152 #1112153 Cross-References: CVE-2018-13785 CVE-2018-16435 CVE-2018-3136 CVE-2018-3139 CVE-2018-3149 CVE-2018-3169 CVE-2018-3180 CVE-2018-3183 CVE-2018-3214 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes 9 vulnerabilities is now available. Description: This update for java-1_8_0-openjdk to version 8u191 fixes the following issues: Security issues fixed: - CVE-2018-3136: Manifest better support (bsc#1112142) - CVE-2018-3139: Better HTTP Redirection (bsc#1112143) - CVE-2018-3149: Enhance JNDI lookups (bsc#1112144) - CVE-2018-3169: Improve field accesses (bsc#1112146) - CVE-2018-3180: Improve TLS connections stability (bsc#1112147) - CVE-2018-3214: Better RIFF reading support (bsc#1112152) - CVE-2018-13785: Upgrade JDK 8u to libpng 1.6.35 (bsc#1112153) - CVE-2018-3183: Improve script engine support (bsc#1112148) - CVE-2018-16435: heap-based buffer overflow in SetData function in cmsIT8LoadFromFile This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-43=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-43=1 Package List: - openSUSE Leap 42.3 (i586x86_64): java-1_8_0-openjdk-1.8.0.191-30.1 java-1_8_0-openjdk-accessibility-1.8.0.191-30.1 java-1_8_0-openjdk-debuginfo-1.8.0.191-30.1 java-1_8_0-openjdk-debugsource-1.8.0.191-30.1 java-1_8_0-openjdk-demo-1.8.0.191-30.1 java-1_8_0-openjdk-demo-debuginfo-1.8.0.191-30.1 java-1_8_0-openjdk-devel-1.8.0.191-30.1 java-1_8_0-openjdk-devel-debuginfo-1.8.0.191-30.1 java-1_8_0-openjdk-headless-1.8.0.191-30.1 java-1_8_0-openjdk-headless-debuginfo-1.8.0.191-30.1 java-1_8_0-openjdk-src-1.8.0.191-30.1 - openSUSE Leap 42.3 (noarch): java-1_8_0-openjdk-javadoc-1.8.0.191-30.1 - openSUSE Leap 15.0 (i586 x86_64): java-1_8_0-openjdk-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-accessibility-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-debuginfo-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-debugsource-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-demo-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-demo-debuginfo-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-devel-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-devel-debuginfo-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-headless-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-headless-debuginfo-1.8.0.191-lp150.2.9.2 java-1_8_0-openjdk-src-1.8.0.191-lp150.2.9.2 - openSUSE Leap 15.0 (noarch): java-1_8_0-openjdk-javadoc-1.8.0.191-lp150.2.9.2 References: https://www.suse.com/security/cve/CVE-2018-13785.html https://www.suse.com/security/cve/CVE-2018-16435.html https://www.suse.com/security/cve/CVE-2018-3136.html https://www.suse.com/security/cve/CVE-2018-3139.html https://www.suse.com/security/cve/CVE-2018-3149.html https://www.suse.com/security/cve/CVE-2018-3169.html https://www.suse.com/security/cve/CVE-2018-3180.html https://www.suse.com/security/cve/CVE-2018-3183.html https://www.suse.com/security/cve/CVE-2018-3214.html https://bugzilla.suse.com/1112142 https://bugzilla.suse.com/1112143 https://bugzilla.suse.com/1112144 https://bugzilla.suse.com/1112146 https://bugzilla.suse.com/1112147 https://bugzilla.suse.com/1112148 https://bugzilla.suse.com/1112152 https://bugzilla.suse.com/1112153 -- . This critical patch for Fedora resolves 12 vulnerabilities in python3-3.8.10 successfully. Explore for further information.. openSUSE Update, Java Security Fix, Important Patch, Java OpenJDK. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 12, 2019 Important OpenSUSE
100

SUSE OpenStack Cloud Critical Update: Python-3_8_0 Security Patch

An update that fixes 13 vulnerabilities is now available. . SUSE Security Update: Security update for java-1_7_0-openjdk ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0049-1 Rating: important References: #1101644 #1101645 #1101651 #1101656 #1112142 #1112143 #1112144 #1112146 #1112147 #1112152 #1112153 Cross-References: CVE-2018-13785 CVE-2018-16435 CVE-2018-2938 CVE-2018-2940 CVE-2018-2952 CVE-2018-2973 CVE-2018-3136 CVE-2018-3139 CVE-2018-3149 CVE-2018-3169 CVE-2018-3180 CVE-2018-3214 CVE-2018-3639 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS SUSE Linux Enterprise Desktop 12-SP4 SUSE Linux Enterprise Desktop 12-SP3 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. Description: This update for java-1_7_0-openjdk to version 7u201 fixes the following issues: Security issues fixed: - CVE-2018-3136: Manifest better support (bsc#1112142) - CVE-2018-3139: Better HTTP Redirection (bsc#1112143) - CVE-2018-3149: Enhance JNDI lookups (bsc#1112144) - CVE-2018-3169: Improve field accesses (bsc#1112146) - CVE-2018-3180: Improve TLS connections stability (bsc#1112147) - CVE-2018-3214: Better RIFF reading support (bsc#1112152) - CVE-2018-13785: Upgrade JDK 8u to libpng 1.6.35(bsc#1112153) - CVE-2018-16435: heap-based buffer overflow in SetData function in cmsIT8LoadFromFile - CVE-2018-2938: Support Derby connections (bsc#1101644) - CVE-2018-2940: Better stack walking (bsc#1101645) - CVE-2018-2952: Exception to Pattern Syntax (bsc#1101651) - CVE-2018-2973: Improve LDAP support (bsc#1101656) - CVE-2018-3639 cpu speculative store bypass mitigation Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-49=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-49=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-49=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-49=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-49=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-49=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-49=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2019-49=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-49=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-49=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-49=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 - SUSE Enterprise Storage 4 (x86_64): java-1_7_0-openjdk-1.7.0.201-43.18.1 java-1_7_0-openjdk-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-debugsource-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-1.7.0.201-43.18.1 java-1_7_0-openjdk-demo-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-1.7.0.201-43.18.1 java-1_7_0-openjdk-devel-debuginfo-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-1.7.0.201-43.18.1 java-1_7_0-openjdk-headless-debuginfo-1.7.0.201-43.18.1 References: https://www.suse.com/security/cve/CVE-2018-13785.html https://www.suse.com/security/cve/CVE-2018-16435.html https://www.suse.com/security/cve/CVE-2018-2938.html https://www.suse.com/security/cve/CVE-2018-2940.html https://www.suse.com/security/cve/CVE-2018-2952.html https://www.suse.com/security/cve/CVE-2018-2973.html https://www.suse.com/security/cve/CVE-2018-3136.html https://www.suse.com/security/cve/CVE-2018-3139.html https://www.suse.com/security/cve/CVE-2018-3149.html https://www.suse.com/security/cve/CVE-2018-3169.html https://www.suse.com/security/cve/CVE-2018-3180.html https://www.suse.com/security/cve/CVE-2018-3214.html https://www.suse.com/security/cve/CVE-2018-3639.html https://bugzilla.suse.com/1101644 https://bugzilla.suse.com/1101645 https://bugzilla.suse.com/1101651 https://bugzilla.suse.com/1101656 https://bugzilla.suse.com/1112142 https://bugzilla.suse.com/1112143 https://bugzilla.suse.com/1112144 https://bugzilla.suse.com/1112146 https://bugzilla.suse.com/1112147 https://bugzilla.suse.com/1112152 https://bugzilla.suse.com/1112153 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Important SUSE update released for java-1_8_0-openjdk tackling multiple vulnerabilities with essential patch guidelines.. SUSE Update, Java OpenJDK, Security Fixes, Critical Patch, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 09, 2019 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200