Oval Definition:oval:org.opensuse.security:def:67579
Revision Date:2022-01-04Version:1
Title:Security update for java-1_8_0-ibm (Important) (in QA)
Description:

This update for java-1_8_0-ibm fixes the following issues:

- Update to Java 8.0 Service Refresh 7 Fix Pack 0 - CVE-2021-41035: before version 0.29.0, the openj9 JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. (bsc#1194198, bsc#1192052) - CVE-2021-35586: Excessive memory allocation in BMPImageReader. (bsc#1191914) - CVE-2021-35564: Certificates with end dates too far in the future can corrupt keystore. (bsc#1191913) - CVE-2021-35559: Excessive memory allocation in RTFReader. (bsc#1191911) - CVE-2021-35556: Excessive memory allocation in RTFParser. (bsc#1191910) - CVE-2021-35565: Loop in HttpsServer triggered during TLS session close. (bsc#1191909) - CVE-2021-35588: Incomplete validation of inner class references in ClassFileParser. (bsc#1191905) - CVE-2021-2341: Fixed a flaw inside the FtpClient. (bsc#1188564) - CVE-2021-2369: JAR file handling problem containing multiple MANIFEST.MF files. (bsc#1188565) - CVE-2021-2163: Incomplete enforcement of JAR signing disabled algorithms. (bsc#1185055) - CVE-2021-35560: Fixed a vulnerability in the component Deployment. (bsc#1191902) - CVE-2021-35578: Fixed unexpected exception raised during TLS handshake. (bsc#1191904)

This patch is currently in QA and not yet available for download.
Family:unixClass:patch
Status:Reference(s):1185055
1188564
1188565
1191902
1191904
1191905
1191909
1191910
1191911
1191913
1191914
1192052
1194198
1194232
CVE-2006-2607
CVE-2010-0424
CVE-2015-2059
CVE-2015-8948
CVE-2016-6261
CVE-2016-6262
CVE-2016-6263
CVE-2017-14062
CVE-2021-2163
CVE-2021-2341
CVE-2021-2369
CVE-2021-35556
CVE-2021-35559
CVE-2021-35560
CVE-2021-35564
CVE-2021-35565
CVE-2021-35578
CVE-2021-35586
CVE-2021-35588
CVE-2021-41035
Platform(s):SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for Legacy 15 SP3
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Manager Proxy 4.2
SUSE Manager Server 4.2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Legacy 15 SP3 is installed
  • AND Package Information
  • java-1_8_0-ibm-1.8.0_sr7.0-3.53.1 is installed
  • OR java-1_8_0-ibm-alsa-1.8.0_sr7.0-3.53.1 is installed
  • OR java-1_8_0-ibm-devel-1.8.0_sr7.0-3.53.1 is installed
  • OR java-1_8_0-ibm-plugin-1.8.0_sr7.0-3.53.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • cron-4.2-4 is installed
  • OR cronie-1.5.1-4 is installed
  • BACK