Security update for java-11-openjdk
This update for java-11-openjdk to version jdk-11.0.4+11 fixes the following issues: Security issues fixed: - CVE-2019-2745: Improved ECC Implementation (bsc#1141784). - CVE-2019-2762: Exceptional throw cases (bsc#1141782). - CVE-2019-2766: Improve file protocol handling (bsc#1141789). - CVE-2019-2769: Better copies of CopiesList (bsc#1141783). - CVE-2019-2786: More limited privilege usage (bsc#1141787). - CVE-2019-7317: Improve PNG support options (bsc#1141780). - CVE-2019-2818: Better Poly1305 support (bsc#1141788). - CVE-2019-2816: Normalize normalization (bsc#1141785). - CVE-2019-2821: Improve TLS negotiation (bsc#1141781). - Certificate validation improvements Non-security issues fixed: - Do not fail installation when the manpages are not present (bsc#1115375) - Backport upstream fix for JDK-8208602: Cannot read PEM X.509 cert if there is whitespace after the header or footer (bsc#1140461) This update was imported from the SUSE:SLE-15:Update update project.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for java-11-openjdk to version jdk-11.0.4+11 fixes the following issues: Security issues fixed: - CVE-2019-2745: Improved ECC Implementation (bsc#1141784). - CVE-2019-2762: Exceptional throw cases (bsc#1141782). - CVE-2019-2766: Improve file protocol handling (bsc#1141789). - CVE-2019-2769: Better copies of CopiesList (bsc#1141783). - CVE-2019-2786: More limited privilege usage (bsc#1141787). - CVE-2019-7317: Improve PNG support options (bsc#1141780). - CVE-2019-2818: Better Poly1305 support (bsc#1141788). - CVE-2019-2816: Normalize normalization (bsc#1141785). - CVE-2019-2821: Improve TLS negotiation (bsc#1141781). - Certificate validation improvements Non-security issues fixed: - Do not fail installation when the manpages are not present (bsc#1115375) - Backport upstream fix for JDK-8208602: Cannot read PEM X.509 cert if there is whitespace after the header or footer (bsc#1140461) This update was imported from the SUSE:SLE-15:Update update project.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1115375
- https://bugzilla.suse.com/1140461
- https://bugzilla.suse.com/1141780
- https://bugzilla.suse.com/1141781
- https://bugzilla.suse.com/1141782
- https://bugzilla.suse.com/1141783
- https://bugzilla.suse.com/1141784
- https://bugzilla.suse.com/1141785
- https://bugzilla.suse.com/1141787
- https://bugzilla.suse.com/1141788
- https://bugzilla.suse.com/1141789
- https://lists.opensuse.org/archives/list/[email protected]/thread/7CWQDHDFTQ5TMYECHR6T3YTCURIWVTNU/#7CWQDHDFTQ5TMYECHR6T3YTCURIWVTNU
- https://www.suse.com/security/cve/CVE-2019-2745
- https://www.suse.com/security/cve/CVE-2019-2762
- https://www.suse.com/security/cve/CVE-2019-2766
- https://www.suse.com/security/cve/CVE-2019-2769
- https://www.suse.com/security/cve/CVE-2019-2786
- https://www.suse.com/security/cve/CVE-2019-2816
- https://www.suse.com/security/cve/CVE-2019-2818
- https://www.suse.com/security/cve/CVE-2019-2821
- https://www.suse.com/security/cve/CVE-2019-7317