SUSE Security Update: Security update for Java
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:0440-1
Rating:             important
References:         #798535 
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP2
                    SUSE Linux Enterprise Server 11 SP2 for VMware
                    SUSE Linux Enterprise Server 11 SP2
                    SUSE Linux Enterprise Java 11 SP2
______________________________________________________________________________

   An update that contains security fixes can now be installed.

Description:


   IBM Java 7 was updated to SR4, fixing various critical
   security issues and  bugs.

   Please see the IBM JDK Alert page for more information:

   https://www.ibm.com/support/pages/java-sdk/
   

   Security issues fixed:

   CVE-2013-1487, CVE-2013-1486, CVE-2013-1478, CVE-2013-0445,
   CVE-2013-1480,  CVE-2013-0441, CVE-2013-1476,
   CVE-2012-1541, CVE-2013-0446, CVE-2012-3342,
   CVE-2013-0442, CVE-2013-0450, CVE-2013-0425, CVE-2013-0426,
   CVE-2013-0428,  CVE-2012-3213, CVE-2013-0419,
   CVE-2013-0423, CVE-2013-0351, CVE-2013-0432,
   CVE-2013-1473, CVE-2013-0435, CVE-2013-0434, CVE-2013-0409,
   CVE-2013-0427,  CVE-2013-0433, CVE-2013-0424,
   CVE-2013-0440, CVE-2013-0438, CVE-2013-0443,
   CVE-2013-1484, CVE-2013-1485, CVE-2013-0437, CVE-2013-0444,
   CVE-2013-0449,  CVE-2013-0431, CVE-2013-0422, CVE-2012-3174.


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP2:

      zypper in -t patch sdksp2-java-1_7_0-ibm-7454

   - SUSE Linux Enterprise Server 11 SP2 for VMware:

      zypper in -t patch slessp2-java-1_7_0-ibm-7454

   - SUSE Linux Enterprise Server 11 SP2:

      zypper in -t patch slessp2-java-1_7_0-ibm-7454

   - SUSE Linux Enterprise Java 11 SP2:

      zypper in -t patch slejsp2-java-1_7_0-ibm-7454

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ppc64 s390x x86_64):

      java-1_7_0-ibm-devel-1.7.0_sr4.0-0.6.1

   - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64):

      java-1_7_0-ibm-1.7.0_sr4.0-0.6.1
      java-1_7_0-ibm-jdbc-1.7.0_sr4.0-0.6.1
      java-1_7_0-ibm-plugin-1.7.0_sr4.0-0.6.1

   - SUSE Linux Enterprise Server 11 SP2 for VMware (i586):

      java-1_7_0-ibm-alsa-1.7.0_sr4.0-0.6.1

   - SUSE Linux Enterprise Server 11 SP2 (i586 ppc64 s390x x86_64):

      java-1_7_0-ibm-1.7.0_sr4.0-0.6.1
      java-1_7_0-ibm-jdbc-1.7.0_sr4.0-0.6.1

   - SUSE Linux Enterprise Server 11 SP2 (i586 x86_64):

      java-1_7_0-ibm-plugin-1.7.0_sr4.0-0.6.1

   - SUSE Linux Enterprise Server 11 SP2 (i586):

      java-1_7_0-ibm-alsa-1.7.0_sr4.0-0.6.1

   - SUSE Linux Enterprise Java 11 SP2 (i586 ppc64 s390x x86_64):

      java-1_7_0-ibm-1.7.0_sr4.0-0.6.1
      java-1_7_0-ibm-devel-1.7.0_sr4.0-0.6.1
      java-1_7_0-ibm-jdbc-1.7.0_sr4.0-0.6.1

   - SUSE Linux Enterprise Java 11 SP2 (i586 x86_64):

      java-1_7_0-ibm-alsa-1.7.0_sr4.0-0.6.1
      java-1_7_0-ibm-plugin-1.7.0_sr4.0-0.6.1


References:

   https://bugzilla.novell.com/798535
   https://login.microfocus.com/nidp/app/login

SuSE: 2013:0440-1: important: Java

March 13, 2013
An update that contains security fixes can now be installed

Summary

IBM Java 7 was updated to SR4, fixing various critical security issues and bugs. Please see the IBM JDK Alert page for more information: https://www.ibm.com/support/pages/java-sdk/ Security issues fixed: CVE-2013-1487, CVE-2013-1486, CVE-2013-1478, CVE-2013-0445, CVE-2013-1480, CVE-2013-0441, CVE-2013-1476, CVE-2012-1541, CVE-2013-0446, CVE-2012-3342, CVE-2013-0442, CVE-2013-0450, CVE-2013-0425, CVE-2013-0426, CVE-2013-0428, CVE-2012-3213, CVE-2013-0419, CVE-2013-0423, CVE-2013-0351, CVE-2013-0432, CVE-2013-1473, CVE-2013-0435, CVE-2013-0434, CVE-2013-0409, CVE-2013-0427, CVE-2013-0433, CVE-2013-0424, CVE-2013-0440, CVE-2013-0438, CVE-2013-0443, CVE-2013-1484, CVE-2013-1485, CVE-2013-0437, CVE-2013-0444, CVE-2013-0449, CVE-2013-0431, CVE-2013-0422, CVE-2012-3174. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp2-java-1_7_0-ibm-7454 - SUSE Linux Enterprise Server 11 SP2 for VMware: zypper in -t patch slessp2-java-1_7_0-ibm-7454 - SUSE Linux Enterprise Server 11 SP2: zypper in -t patch slessp2-java-1_7_0-ibm-7454 - SUSE Linux Enterprise Java 11 SP2: zypper in -t patch slejsp2-java-1_7_0-ibm-7454 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ppc64 s390x x86_64): java-1_7_0-ibm-devel-1.7.0_sr4.0-0.6.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64): java-1_7_0-ibm-1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-jdbc-1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-plugin-1.7.0_sr4.0-0.6.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (i586): java-1_7_0-ibm-alsa-1.7.0_sr4.0-0.6.1 - SUSE Linux Enterprise Server 11 SP2 (i586 ppc64 s390x x86_64): java-1_7_0-ibm-1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-jdbc-1.7.0_sr4.0-0.6.1 - SUSE Linux Enterprise Server 11 SP2 (i586 x86_64): java-1_7_0-ibm-plugin-1.7.0_sr4.0-0.6.1 - SUSE Linux Enterprise Server 11 SP2 (i586): java-1_7_0-ibm-alsa-1.7.0_sr4.0-0.6.1 - SUSE Linux Enterprise Java 11 SP2 (i586 ppc64 s390x x86_64): java-1_7_0-ibm-1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-devel-1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-jdbc-1.7.0_sr4.0-0.6.1 - SUSE Linux Enterprise Java 11 SP2 (i586 x86_64): java-1_7_0-ibm-alsa-1.7.0_sr4.0-0.6.1 java-1_7_0-ibm-plugin-1.7.0_sr4.0-0.6.1

References

#798535

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Java 11 SP2

https://bugzilla.novell.com/798535

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2013:0440-1
Rating: important

Related News