Security update for java-1_8_0-openjdk
This update for java-1_8_0-openjdk fixes the following issues: - Update to version jdk8u151 (icedtea 3.6.0) Security issues fixed: - CVE-2017-10274: Handle smartcard clean up better (bsc#1064071) - CVE-2017-10281: Better queuing priorities (bsc#1064072) - CVE-2017-10285: Unreferenced references (bsc#1064073) - CVE-2017-10295: Better URL connections (bsc#1064075) - CVE-2017-10388: Correct Kerberos ticket grants (bsc#1064086) - CVE-2017-10346: Better invokespecial checks (bsc#1064078) - CVE-2017-10350: Better Base Exceptions (bsc#1064082) - CVE-2017-10347: Better timezone processing (bsc#1064079) - CVE-2017-10349: Better X processing (bsc#1064081) - CVE-2017-10345: Better keystore handling (bsc#1064077) - CVE-2017-10348: Better processing of unresolved permissions (bsc#1064080) - CVE-2017-10357: Process Proxy presentation (bsc#1064085) - CVE-2017-10355: More stable connection processing (bsc#1064083) - CVE-2017-10356: Update storage implementations (bsc#1064084) - CVE-2016-10165: Improve CMS header processing (bsc#1064069) - CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843: Upgrade compression library (bsc#1064070) Bug fixes: - Fix bsc#1032647, bsc#1052009 with btrfs subvolumes and overlayfs
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for java-1_8_0-openjdk fixes the following issues: - Update to version jdk8u151 (icedtea 3.6.0) Security issues fixed: - CVE-2017-10274: Handle smartcard clean up better (bsc#1064071) - CVE-2017-10281: Better queuing priorities (bsc#1064072) - CVE-2017-10285: Unreferenced references (bsc#1064073) - CVE-2017-10295: Better URL connections (bsc#1064075) - CVE-2017-10388: Correct Kerberos ticket grants (bsc#1064086) - CVE-2017-10346: Better invokespecial checks (bsc#1064078) - CVE-2017-10350: Better Base Exceptions (bsc#1064082) - CVE-2017-10347: Better timezone processing (bsc#1064079) - CVE-2017-10349: Better X processing (bsc#1064081) - CVE-2017-10345: Better keystore handling (bsc#1064077) - CVE-2017-10348: Better processing of unresolved permissions (bsc#1064080) - CVE-2017-10357: Process Proxy presentation (bsc#1064085) - CVE-2017-10355: More stable connection processing (bsc#1064083) - CVE-2017-10356: Update storage implementations (bsc#1064084) - CVE-2016-10165: Improve CMS header processing (bsc#1064069) - CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843: Upgrade compression library (bsc#1064070) Bug fixes: - Fix bsc#1032647, bsc#1052009 with btrfs subvolumes and overlayfs
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1032647
- https://bugzilla.suse.com/1052009
- https://bugzilla.suse.com/1064069
- https://bugzilla.suse.com/1064070
- https://bugzilla.suse.com/1064071
- https://bugzilla.suse.com/1064072
- https://bugzilla.suse.com/1064073
- https://bugzilla.suse.com/1064075
- https://bugzilla.suse.com/1064077
- https://bugzilla.suse.com/1064078
- https://bugzilla.suse.com/1064079
- https://bugzilla.suse.com/1064080
- https://bugzilla.suse.com/1064081
- https://bugzilla.suse.com/1064082
- https://bugzilla.suse.com/1064083
- https://bugzilla.suse.com/1064084
- https://bugzilla.suse.com/1064085
- https://bugzilla.suse.com/1064086
- https://www.suse.com/security/cve/CVE-2016-10165
- https://www.suse.com/security/cve/CVE-2016-9840
- https://www.suse.com/security/cve/CVE-2016-9841
- https://www.suse.com/security/cve/CVE-2016-9842
- https://www.suse.com/security/cve/CVE-2016-9843
- https://www.suse.com/security/cve/CVE-2017-10274
- https://www.suse.com/security/cve/CVE-2017-10281
- https://www.suse.com/security/cve/CVE-2017-10285
- https://www.suse.com/security/cve/CVE-2017-10295
- https://www.suse.com/security/cve/CVE-2017-10345
- https://www.suse.com/security/cve/CVE-2017-10346
- https://www.suse.com/security/cve/CVE-2017-10347
- https://www.suse.com/security/cve/CVE-2017-10348
- https://www.suse.com/security/cve/CVE-2017-10349
- https://www.suse.com/security/cve/CVE-2017-10350
- https://www.suse.com/security/cve/CVE-2017-10355
- https://www.suse.com/security/cve/CVE-2017-10356
- https://www.suse.com/security/cve/CVE-2017-10357
- https://www.suse.com/security/cve/CVE-2017-10388
- https://www.suse.com/support/update/announcement/2017/suse-su-20172989-1/