Oval Definition:oval:org.opensuse.security:def:64969
Revision Date:2020-12-01Version:1
Title:Security update for java-11-openjdk (Important)
Description:

This update for java-11-openjdk fixes the following issues:

Java was updated to jdk-11.0.7+10 (April 2020 CPU, bsc#1169511).

Security issues fixed:

- CVE-2020-2754: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2755: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2756: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2757: Fixed an object deserialization issue that could have resulted in denial of service via crafted serialized input (bsc#1169511). - CVE-2020-2767: Fixed an incorrect handling of certificate messages during TLS handshakes (bsc#1169511). - CVE-2020-2773: Fixed the incorrect handling of exceptions thrown by unmarshalKeyInfo() and unmarshalXMLSignature() (bsc#1169511). - CVE-2020-2778: Fixed the incorrect handling of SSLParameters in setAlgorithmConstraints(), which could have been abused to override the defined systems security policy and lead to the use of weak crypto algorithms (bsc#1169511). - CVE-2020-2781: Fixed the incorrect re-use of single null TLS sessions (bsc#1169511). - CVE-2020-2800: Fixed an HTTP header injection issue caused by mishandling of CR/LF in header values (bsc#1169511). - CVE-2020-2803: Fixed a boundary check and type check issue that could have led to a sandbox bypass (bsc#1169511). - CVE-2020-2805: Fixed a boundary check and type check issue that could have led to a sandbox bypass (bsc#1169511). - CVE-2020-2816: Fixed an incorrect handling of application data packets during TLS handshakes (bsc#1169511). - CVE-2020-2830: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511).
Family:unixClass:patch
Status:Reference(s):1055014
1055186
1061843
1065600
1065729
1066382
1077428
1126826
1126829
1126831
1129923
1134760
1140126
1142649
1143609
1149032
1152489
1153768
1153770
1157755
1160254
1160590
1163333
1163592
1163744
1164648
1166146
1166166
1167030
1167462
1169511
1170415
1174052
1174748
1174969
1175052
1175070
1175071
1175074
1175306
1175721
1175749
1175898
1176354
1176485
1176713
1177086
1177281
1177353
1177410
1177411
1177470
1177739
1177749
1177750
1177754
1177755
1177765
1177766
1177799
1177801
1177814
1177817
1177854
1177855
1177856
1177861
1178002
1178079
1178123
1178166
1178173
1178175
1178176
1178177
1178183
1178184
1178185
1178186
1178190
1178191
1178246
1178255
1178307
1178330
1178393
1178395
1178461
1178579
1178581
1178584
1178585
CVE-2019-12972
CVE-2019-14250
CVE-2019-14444
CVE-2019-17450
CVE-2019-17451
CVE-2019-9074
CVE-2019-9075
CVE-2019-9077
CVE-2020-11984
CVE-2020-11993
CVE-2020-14351
CVE-2020-16120
CVE-2020-25285
CVE-2020-25656
CVE-2020-25668
CVE-2020-25704
CVE-2020-25705
CVE-2020-2754
CVE-2020-2755
CVE-2020-2756
CVE-2020-2757
CVE-2020-2767
CVE-2020-2773
CVE-2020-2778
CVE-2020-2781
CVE-2020-2800
CVE-2020-2803
CVE-2020-2805
CVE-2020-2816
CVE-2020-2830
CVE-2020-8694
CVE-2020-9490
openSUSE-SU-2020:1285-1
SUSE-SU-2020:1511-1
SUSE-SU-2020:3060-1
Platform(s):openSUSE Leap 15.2
SUSE Linux Enterprise Module for Basesystem 15 SP1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • apache2-2.4.43-lp152.2.3 is installed
  • OR apache2-devel-2.4.43-lp152.2.3 is installed
  • OR apache2-doc-2.4.43-lp152.2.3 is installed
  • OR apache2-event-2.4.43-lp152.2.3 is installed
  • OR apache2-example-pages-2.4.43-lp152.2.3 is installed
  • OR apache2-prefork-2.4.43-lp152.2.3 is installed
  • OR apache2-utils-2.4.43-lp152.2.3 is installed
  • OR apache2-worker-2.4.43-lp152.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • java-11-openjdk-11.0.7.0-3.42 is installed
  • OR java-11-openjdk-demo-11.0.7.0-3.42 is installed
  • OR java-11-openjdk-devel-11.0.7.0-3.42 is installed
  • OR java-11-openjdk-headless-11.0.7.0-3.42 is installed
  • BACK