[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2024:0619-1 -- SLES java-1_8_0-ibm

ID: oval:org.secpod.oval:def:89051543Date: (C)2024-04-26   (M)2024-04-29
Class: PATCHFamily: unix




This update for java-1_8_0-ibm fixes the following issues: Update to Java 8.0 Service Refresh 8 Fix Pack 20: [bsc#1219843] Security fixes: * CVE-2023-33850: Fixed information disclosure vulnerability due to the consumed GSKit library . * CVE-2024-20932: Fixed incorrect handling of ZIP files with duplicate entries . * CVE-2024-20952: Fixed RSA padding issue and timing side-channel attack against TLS . * CVE-2024-20918: Fixed array out-of-bounds access due to missing range check in C1 compiler . * CVE-2024-20921: Fixed range check loop optimization issue . * CVE-2024-20919: Fixed JVM class file verifier flaw allows unverified bytecode execution . * CVE-2024-20926: Fixed arbitrary Java code execution in Nashorn . * CVE-2024-20945: Fixed logging of digital signature private keys .

Platform:
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server 15 SP3
Product:
java-1_8_0-ibm
Reference:
SUSE-SU-2024:0619-1
CVE-2023-33850
CVE-2024-20918
CVE-2024-20919
CVE-2024-20921
CVE-2024-20926
CVE-2024-20932
CVE-2024-20945
CVE-2024-20952
CVE    8
CVE-2023-33850
CVE-2024-20918
CVE-2024-20952
CVE-2024-20932
...
CPE    4
cpe:/a:ibm:java-1_8_0-ibm
cpe:/o:suse:suse_linux_enterprise_server:15:sp4
cpe:/o:suse:suse_linux_enterprise_server:15:sp3
cpe:/o:suse:suse_linux_enterprise_server:15:sp2
...

© SecPod Technologies