Security update for java-1_7_0-ibm
This update for java-1_7_0-ibm fixes the following issues: - Update to Java 7.0 Service Refresh 10 Fix Pack 75 [bsc#1180063, bsc#1177943] CVE-2020-14792 CVE-2020-14797 CVE-2020-14782 CVE-2020-14781 CVE-2020-14779 CVE-2020-14798 CVE-2020-14796 CVE-2020-14803 * Class Libraries: - Z/OS specific C function send_file is changing the file pointer position * Security: - Add the new oracle signer certificate - Certificate parsing error - JVM memory growth can be caused by the IBMPKCS11IMPL crypto provider - Remove check for websphere signed jars - sessionid.hashcode generates too many collisions - The Java 8 IBM certpath provider does not honor the user specified system property for CLR connect timeout
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for java-1_7_0-ibm fixes the following issues: - Update to Java 7.0 Service Refresh 10 Fix Pack 75 [bsc#1180063, bsc#1177943] CVE-2020-14792 CVE-2020-14797 CVE-2020-14782 CVE-2020-14781 CVE-2020-14779 CVE-2020-14798 CVE-2020-14796 CVE-2020-14803 * Class Libraries: - Z/OS specific C function send_file is changing the file pointer position * Security: - Add the new oracle signer certificate - Certificate parsing error - JVM memory growth can be caused by the IBMPKCS11IMPL crypto provider - Remove check for websphere signed jars - sessionid.hashcode generates too many collisions - The Java 8 IBM certpath provider does not honor the user specified system property for CLR connect timeout
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1177943
- https://bugzilla.suse.com/1180063
- https://www.suse.com/security/cve/CVE-2020-14779
- https://www.suse.com/security/cve/CVE-2020-14781
- https://www.suse.com/security/cve/CVE-2020-14782
- https://www.suse.com/security/cve/CVE-2020-14792
- https://www.suse.com/security/cve/CVE-2020-14796
- https://www.suse.com/security/cve/CVE-2020-14797
- https://www.suse.com/security/cve/CVE-2020-14798
- https://www.suse.com/security/cve/CVE-2020-14803
- https://www.suse.com/support/update/announcement/2020/suse-su-202014587-1/