[SUSE-SU-2019:2028-1] Security update for java-1_7_0-openjdk

Severity Important
Affected Packages 18
CVEs 10

Security update for java-1_7_0-openjdk

This update for java-1_7_0-openjdk to version 7u231 fixes the following issues:

Security issues fixed:

  • CVE_2019-2426: Improve web server connections (bsc#1134297).
  • CVE-2019-2745: Improved ECC Implementation (bsc#1141784).
  • CVE-2019-2762: Exceptional throw cases (bsc#1141782).
  • CVE-2019-2766: Improve file protocol handling (bsc#1141789).
  • CVE-2019-2769: Better copies of CopiesList (bsc#1141783).
  • CVE-2019-2786: More limited privilege usage (bsc#1141787).
  • CVE-2019-2816: Normalize normalization (bsc#1141785).
  • CVE-2019-2842: Extended AES support (bsc#1141786).
  • CVE-2019-7317: Improve PNG support (bsc#1141780).
  • CVE-2018-3639: fix revision to prefer PR_SPEC_DISABLE_NOEXEC to PR_SPEC_DISABLE (bsc#1087082).
  • Certificate validation improvements
Package Affected Version
pkg:rpm/suse/java-1_7_0-openjdk?arch=x86_64&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk?arch=x86_64&distro=sled-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk?arch=s390x&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk?arch=ppc64le&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk?arch=aarch64&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=x86_64&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=x86_64&distro=sled-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=s390x&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=ppc64le&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=aarch64&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-devel?arch=x86_64&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-devel?arch=s390x&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-devel?arch=ppc64le&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-devel?arch=aarch64&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-demo?arch=x86_64&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-demo?arch=s390x&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-demo?arch=ppc64le&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
pkg:rpm/suse/java-1_7_0-openjdk-demo?arch=aarch64&distro=sles-12&sp=4 < 1.7.0.231-43.27.2
ID
SUSE-SU-2019:2028-1
Severity
important
URL
https://www.suse.com/support/update/announcement/2019/suse-su-20192028-1/
Published
2019-07-31T11:34:53
(5 years ago)
Modified
2019-07-31T11:34:53
(5 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/suse-su-2019_2028-1.json
Suse URL for SUSE-SU-2019:2028-1 https://www.suse.com/support/update/announcement/2019/suse-su-20192028-1/
Suse E-Mail link for SUSE-SU-2019:2028-1 https://lists.suse.com/pipermail/sle-security-updates/2019-July/005762.html
Bugzilla SUSE Bug 1087082 https://bugzilla.suse.com/1087082
Bugzilla SUSE Bug 1134297 https://bugzilla.suse.com/1134297
Bugzilla SUSE Bug 1141780 https://bugzilla.suse.com/1141780
Bugzilla SUSE Bug 1141782 https://bugzilla.suse.com/1141782
Bugzilla SUSE Bug 1141783 https://bugzilla.suse.com/1141783
Bugzilla SUSE Bug 1141784 https://bugzilla.suse.com/1141784
Bugzilla SUSE Bug 1141785 https://bugzilla.suse.com/1141785
Bugzilla SUSE Bug 1141786 https://bugzilla.suse.com/1141786
Bugzilla SUSE Bug 1141787 https://bugzilla.suse.com/1141787
Bugzilla SUSE Bug 1141789 https://bugzilla.suse.com/1141789
CVE SUSE CVE CVE-2018-3639 page https://www.suse.com/security/cve/CVE-2018-3639/
CVE SUSE CVE CVE-2019-2426 page https://www.suse.com/security/cve/CVE-2019-2426/
CVE SUSE CVE CVE-2019-2745 page https://www.suse.com/security/cve/CVE-2019-2745/
CVE SUSE CVE CVE-2019-2762 page https://www.suse.com/security/cve/CVE-2019-2762/
CVE SUSE CVE CVE-2019-2766 page https://www.suse.com/security/cve/CVE-2019-2766/
CVE SUSE CVE CVE-2019-2769 page https://www.suse.com/security/cve/CVE-2019-2769/
CVE SUSE CVE CVE-2019-2786 page https://www.suse.com/security/cve/CVE-2019-2786/
CVE SUSE CVE CVE-2019-2816 page https://www.suse.com/security/cve/CVE-2019-2816/
CVE SUSE CVE CVE-2019-2842 page https://www.suse.com/security/cve/CVE-2019-2842/
CVE SUSE CVE CVE-2019-7317 page https://www.suse.com/security/cve/CVE-2019-7317/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/java-1_7_0-openjdk?arch=x86_64&distro=sles-12&sp=4 suse java-1_7_0-openjdk < 1.7.0.231-43.27.2 sles-12 x86_64
Affected pkg:rpm/suse/java-1_7_0-openjdk?arch=x86_64&distro=sled-12&sp=4 suse java-1_7_0-openjdk < 1.7.0.231-43.27.2 sled-12 x86_64
Affected pkg:rpm/suse/java-1_7_0-openjdk?arch=s390x&distro=sles-12&sp=4 suse java-1_7_0-openjdk < 1.7.0.231-43.27.2 sles-12 s390x
Affected pkg:rpm/suse/java-1_7_0-openjdk?arch=ppc64le&distro=sles-12&sp=4 suse java-1_7_0-openjdk < 1.7.0.231-43.27.2 sles-12 ppc64le
Affected pkg:rpm/suse/java-1_7_0-openjdk?arch=aarch64&distro=sles-12&sp=4 suse java-1_7_0-openjdk < 1.7.0.231-43.27.2 sles-12 aarch64
Affected pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=x86_64&distro=sles-12&sp=4 suse java-1_7_0-openjdk-headless < 1.7.0.231-43.27.2 sles-12 x86_64
Affected pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=x86_64&distro=sled-12&sp=4 suse java-1_7_0-openjdk-headless < 1.7.0.231-43.27.2 sled-12 x86_64
Affected pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=s390x&distro=sles-12&sp=4 suse java-1_7_0-openjdk-headless < 1.7.0.231-43.27.2 sles-12 s390x
Affected pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=ppc64le&distro=sles-12&sp=4 suse java-1_7_0-openjdk-headless < 1.7.0.231-43.27.2 sles-12 ppc64le
Affected pkg:rpm/suse/java-1_7_0-openjdk-headless?arch=aarch64&distro=sles-12&sp=4 suse java-1_7_0-openjdk-headless < 1.7.0.231-43.27.2 sles-12 aarch64
Affected pkg:rpm/suse/java-1_7_0-openjdk-devel?arch=x86_64&distro=sles-12&sp=4 suse java-1_7_0-openjdk-devel < 1.7.0.231-43.27.2 sles-12 x86_64
Affected pkg:rpm/suse/java-1_7_0-openjdk-devel?arch=s390x&distro=sles-12&sp=4 suse java-1_7_0-openjdk-devel < 1.7.0.231-43.27.2 sles-12 s390x
Affected pkg:rpm/suse/java-1_7_0-openjdk-devel?arch=ppc64le&distro=sles-12&sp=4 suse java-1_7_0-openjdk-devel < 1.7.0.231-43.27.2 sles-12 ppc64le
Affected pkg:rpm/suse/java-1_7_0-openjdk-devel?arch=aarch64&distro=sles-12&sp=4 suse java-1_7_0-openjdk-devel < 1.7.0.231-43.27.2 sles-12 aarch64
Affected pkg:rpm/suse/java-1_7_0-openjdk-demo?arch=x86_64&distro=sles-12&sp=4 suse java-1_7_0-openjdk-demo < 1.7.0.231-43.27.2 sles-12 x86_64
Affected pkg:rpm/suse/java-1_7_0-openjdk-demo?arch=s390x&distro=sles-12&sp=4 suse java-1_7_0-openjdk-demo < 1.7.0.231-43.27.2 sles-12 s390x
Affected pkg:rpm/suse/java-1_7_0-openjdk-demo?arch=ppc64le&distro=sles-12&sp=4 suse java-1_7_0-openjdk-demo < 1.7.0.231-43.27.2 sles-12 ppc64le
Affected pkg:rpm/suse/java-1_7_0-openjdk-demo?arch=aarch64&distro=sles-12&sp=4 suse java-1_7_0-openjdk-demo < 1.7.0.231-43.27.2 sles-12 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...