Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:2083-1

Опубликовано: 27 июл. 2018
Источник: suse-cvrf

Описание

Security update for java-10-openjdk

This update for OpenJDK 10.0.2 fixes the following security issues:

  • CVE-2018-2940: the libraries sub-component contained an easily exploitable vulnerability that allowed attackers to compromise Java SE or Java SE Embedded over the network, potentially gaining unauthorized read access to data that's accessible to the server. [bsc#1101645]

  • CVE-2018-2952: the concurrency sub-component contained a difficult to exploit vulnerability that allowed attackers to compromise Java SE, Java SE Embedded, or JRockit over the network. This issue could have been abused to mount a partial denial-of-service attack on the server. [bsc#1101651]

  • CVE-2018-2972: the security sub-component contained a difficult to exploit vulnerability that allowed attackers to compromise Java SE over the network, potentially gaining unauthorized access to critical data or complete access to all Java SE accessible data. [bsc#1101655)

  • CVE-2018-2973: the JSSE sub-component contained a difficult to exploit vulnerability allowed attackers to compromise Java SE or Java SE Embedded over the network, potentially gaining the ability to create, delete or modify critical data or all Java SE, Java SE Embedded accessible data without authorization. [bsc#1101656]

Furthemore, the following bugs were fixed:

  • Properly remove the existing alternative for java before reinstalling it. [bsc#1096420]

  • idlj was moved to the *-devel package. [bsc#1096420]

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15
java-10-openjdk-10.0.2.0-3.3.3
java-10-openjdk-demo-10.0.2.0-3.3.3
java-10-openjdk-devel-10.0.2.0-3.3.3
java-10-openjdk-headless-10.0.2.0-3.3.3

Описание

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-demo-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-devel-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-headless-10.0.2.0-3.3.3

Ссылки

Описание

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-demo-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-devel-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-headless-10.0.2.0-3.3.3

Ссылки

Описание

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). The supported version that is affected is Java SE: 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-demo-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-devel-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-headless-10.0.2.0-3.3.3

Ссылки

Описание

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-demo-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-devel-10.0.2.0-3.3.3
SUSE Linux Enterprise Module for Basesystem 15:java-10-openjdk-headless-10.0.2.0-3.3.3

Ссылки
Уязвимость SUSE-SU-2018:2083-1