Oval Definition:oval:org.opensuse.security:def:69329
Revision Date:2020-12-01Version:1
Title:Security update for java-11-openjdk (Important)
Description:

This update for java-11-openjdk fixes the following issues:

Java was updated to jdk-11.0.7+10 (April 2020 CPU, bsc#1169511).

Security issues fixed:

- CVE-2020-2754: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2755: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2756: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2757: Fixed an object deserialization issue that could have resulted in denial of service via crafted serialized input (bsc#1169511). - CVE-2020-2767: Fixed an incorrect handling of certificate messages during TLS handshakes (bsc#1169511). - CVE-2020-2773: Fixed the incorrect handling of exceptions thrown by unmarshalKeyInfo() and unmarshalXMLSignature() (bsc#1169511). - CVE-2020-2778: Fixed the incorrect handling of SSLParameters in setAlgorithmConstraints(), which could have been abused to override the defined systems security policy and lead to the use of weak crypto algorithms (bsc#1169511). - CVE-2020-2781: Fixed the incorrect re-use of single null TLS sessions (bsc#1169511). - CVE-2020-2800: Fixed an HTTP header injection issue caused by mishandling of CR/LF in header values (bsc#1169511). - CVE-2020-2803: Fixed a boundary check and type check issue that could have led to a sandbox bypass (bsc#1169511). - CVE-2020-2805: Fixed a boundary check and type check issue that could have led to a sandbox bypass (bsc#1169511). - CVE-2020-2816: Fixed an incorrect handling of application data packets during TLS handshakes (bsc#1169511). - CVE-2020-2830: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511).
Family:unixClass:patch
Status:Reference(s):1138301
1138302
1138303
1138305
1167462
1169511
CVE-2019-10161
CVE-2019-10166
CVE-2019-10167
CVE-2019-10168
CVE-2020-2754
CVE-2020-2755
CVE-2020-2756
CVE-2020-2757
CVE-2020-2767
CVE-2020-2773
CVE-2020-2778
CVE-2020-2781
CVE-2020-2800
CVE-2020-2803
CVE-2020-2805
CVE-2020-2816
CVE-2020-2830
SUSE-SU-2019:1643-1
SUSE-SU-2020:1511-2
Platform(s):SUSE Linux Enterprise Module for additional PackageHub packages 15 SP1
SUSE Linux Enterprise Module for Server Applications 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for additional PackageHub packages 15 SP1 is installed
  • AND Package Information
  • java-11-openjdk-11.0.7.0-3.42 is installed
  • OR java-11-openjdk-javadoc-11.0.7.0-3.42 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND Package Information
  • libvirt-5.1.0-8.6 is installed
  • OR libvirt-admin-5.1.0-8.6 is installed
  • OR libvirt-bash-completion-5.1.0-8.6 is installed
  • OR libvirt-client-5.1.0-8.6 is installed
  • OR libvirt-daemon-5.1.0-8.6 is installed
  • OR libvirt-daemon-config-network-5.1.0-8.6 is installed
  • OR libvirt-daemon-config-nwfilter-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-interface-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-libxl-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-lxc-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-network-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-nodedev-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-nwfilter-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-qemu-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-secret-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-storage-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-storage-core-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-storage-disk-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-storage-iscsi-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-storage-logical-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-storage-mpath-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-storage-rbd-5.1.0-8.6 is installed
  • OR libvirt-daemon-driver-storage-scsi-5.1.0-8.6 is installed
  • OR libvirt-daemon-hooks-5.1.0-8.6 is installed
  • OR libvirt-daemon-lxc-5.1.0-8.6 is installed
  • OR libvirt-daemon-qemu-5.1.0-8.6 is installed
  • OR libvirt-daemon-xen-5.1.0-8.6 is installed
  • OR libvirt-devel-5.1.0-8.6 is installed
  • OR libvirt-doc-5.1.0-8.6 is installed
  • OR libvirt-lock-sanlock-5.1.0-8.6 is installed
  • OR libvirt-nss-5.1.0-8.6 is installed
  • BACK