SUSE Security Update: Security update for openjdk
______________________________________________________________________________

Announcement ID:    SUSE-SU-2014:0961-1
Rating:             important
References:         #887530 
Cross-References:   CVE-2014-2483 CVE-2014-2490 CVE-2014-4208
                    CVE-2014-4209 CVE-2014-4216 CVE-2014-4218
                    CVE-2014-4219 CVE-2014-4220 CVE-2014-4221
                    CVE-2014-4223 CVE-2014-4227 CVE-2014-4244
                    CVE-2014-4247 CVE-2014-4252 CVE-2014-4262
                    CVE-2014-4263 CVE-2014-4264 CVE-2014-4265
                    CVE-2014-4266 CVE-2014-4268
Affected Products:
                    SUSE Linux Enterprise Desktop 11 SP3
______________________________________________________________________________

   An update that fixes 20 vulnerabilities is now available.
   It includes one version update.

Description:


   This Critical Patch Update contains 20 new security fixes for Oracle Java
   SE. All of these vulnerabilities could have been remotely exploitable
   without authentication, i.e., could be exploited over a network without
   the need for a username and password.

   Security Issues:

       * CVE-2014-4227
         
       * CVE-2014-4219
         
       * CVE-2014-2490
         
       * CVE-2014-4216
         
       * CVE-2014-4247
         
       * CVE-2014-2483
         
       * CVE-2014-4223
         
       * CVE-2014-4262
         
       * CVE-2014-4209
         
       * CVE-2014-4265
         
       * CVE-2014-4220
         
       * CVE-2014-4218
         
       * CVE-2014-4252
         
       * CVE-2014-4266
         
       * CVE-2014-4268
         
       * CVE-2014-4264
         
       * CVE-2014-4221
         
       * CVE-2014-4244
         
       * CVE-2014-4263
         
       * CVE-2014-4208
         


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Desktop 11 SP3:

      zypper in -t patch sledsp3-java-1_7_0-openjdk-9543

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 1.7.0.65]:

      java-1_7_0-openjdk-1.7.0.65-0.7.4
      java-1_7_0-openjdk-demo-1.7.0.65-0.7.4
      java-1_7_0-openjdk-devel-1.7.0.65-0.7.4


References:

   https://www.suse.com/security/cve/CVE-2014-2483.html
   https://www.suse.com/security/cve/CVE-2014-2490.html
   https://www.suse.com/security/cve/CVE-2014-4208.html
   https://www.suse.com/security/cve/CVE-2014-4209.html
   https://www.suse.com/security/cve/CVE-2014-4216.html
   https://www.suse.com/security/cve/CVE-2014-4218.html
   https://www.suse.com/security/cve/CVE-2014-4219.html
   https://www.suse.com/security/cve/CVE-2014-4220.html
   https://www.suse.com/security/cve/CVE-2014-4221.html
   https://www.suse.com/security/cve/CVE-2014-4223.html
   https://www.suse.com/security/cve/CVE-2014-4227.html
   https://www.suse.com/security/cve/CVE-2014-4244.html
   https://www.suse.com/security/cve/CVE-2014-4247.html
   https://www.suse.com/security/cve/CVE-2014-4252.html
   https://www.suse.com/security/cve/CVE-2014-4262.html
   https://www.suse.com/security/cve/CVE-2014-4263.html
   https://www.suse.com/security/cve/CVE-2014-4264.html
   https://www.suse.com/security/cve/CVE-2014-4265.html
   https://www.suse.com/security/cve/CVE-2014-4266.html
   https://www.suse.com/security/cve/CVE-2014-4268.html
   https://bugzilla.novell.com/887530
   https://scc.suse.com:443/patches/

SuSE: 2014:0961-1: important: openjdk

August 4, 2014
An update that fixes 20 vulnerabilities is now available

Summary

This Critical Patch Update contains 20 new security fixes for Oracle Java SE. All of these vulnerabilities could have been remotely exploitable without authentication, i.e., could be exploited over a network without the need for a username and password. Security Issues: * CVE-2014-4227 * CVE-2014-4219 * CVE-2014-2490 * CVE-2014-4216 * CVE-2014-4247 * CVE-2014-2483 * CVE-2014-4223 * CVE-2014-4262 * CVE-2014-4209 * CVE-2014-4265 * CVE-2014-4220 * CVE-2014-4218 * CVE-2014-4252 * CVE-2014-4266 * CVE-2014-4268 * CVE-2014-4264 * CVE-2014-4221 * CVE-2014-4244 * CVE-2014-4263 * CVE-2014-4208 Patch Instructions: To install this SUSE...

Read the Full Advisory

References

#887530

Cross- CVE-2014-2483 CVE-2014-2490 CVE-2014-4208

CVE-2014-4209 CVE-2014-4216 CVE-2014-4218

CVE-2014-4219 CVE-2014-4220 CVE-2014-4221

CVE-2014-4223 CVE-2014-4227 CVE-2014-4244

CVE-2014-4247 CVE-2014-4252 CVE-2014-4262

CVE-2014-4263 CVE-2014-4264 CVE-2014-4265

CVE-2014-4266 CVE-2014-4268

Affected Products:

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-2483.html

https://www.suse.com/security/cve/CVE-2014-2490.html

https://www.suse.com/security/cve/CVE-2014-4208.html

https://www.suse.com/security/cve/CVE-2014-4209.html

https://www.suse.com/security/cve/CVE-2014-4216.html

https://www.suse.com/security/cve/CVE-2014-4218.html

https://www.suse.com/security/cve/CVE-2014-4219.html

https://www.suse.com/security/cve/CVE-2014-4220.html

https://www.suse.com/security/cve/CVE-2014-4221.html

https:...

Read the Full Advisory

Severity
Announcement ID: SUSE-SU-2014:0961-1
Rating: important

Related News