Security update for java-1_7_0-ibm
This IBM Java 1.7.0 SR9 FP40 release fixes the following issues: Security issues fixed: - CVE-2016-0264: buffer overflow vulnerability in the IBM JVM (bsc#977648) - CVE-2016-0363: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix (bsc#977650) - CVE-2016-0376: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix (bsc#977646) - The following CVEs got also fixed during this update. (bsc#979252) CVE-2016-3443, CVE-2016-0687, CVE-2016-0686, CVE-2016-3427, CVE-2016-3449, CVE-2016-3422, CVE-2016-3426
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This IBM Java 1.7.0 SR9 FP40 release fixes the following issues: Security issues fixed: - CVE-2016-0264: buffer overflow vulnerability in the IBM JVM (bsc#977648) - CVE-2016-0363: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix (bsc#977650) - CVE-2016-0376: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix (bsc#977646) - The following CVEs got also fixed during this update. (bsc#979252) CVE-2016-3443, CVE-2016-0687, CVE-2016-0686, CVE-2016-3427, CVE-2016-3449, CVE-2016-3422, CVE-2016-3426
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/977646
- https://bugzilla.suse.com/977648
- https://bugzilla.suse.com/977650
- https://bugzilla.suse.com/979252
- https://www.suse.com/security/cve/CVE-2016-0264
- https://www.suse.com/security/cve/CVE-2016-0363
- https://www.suse.com/security/cve/CVE-2016-0376
- https://www.suse.com/security/cve/CVE-2016-0686
- https://www.suse.com/security/cve/CVE-2016-0687
- https://www.suse.com/security/cve/CVE-2016-3422
- https://www.suse.com/security/cve/CVE-2016-3426
- https://www.suse.com/security/cve/CVE-2016-3427
- https://www.suse.com/security/cve/CVE-2016-3443
- https://www.suse.com/security/cve/CVE-2016-3449
- https://www.suse.com/support/update/announcement/2016/suse-su-20161378-1/