FlawAtlas
Search the atlas
SUSE-SU-2021:3797-1 Not scored

Security update for java-1_7_0-openjdk

This update for java-1_7_0-openjdk fixes the following issues: Update to OpenJDK 7u321 (October 2021 CPU): - CVE-2021-35550: Fixed weak ciphers preferred over stronger ones for TLS (bsc#1191901). - CVE-2021-35556: Fixed excessive memory allocation in RTFParser (bsc#1191910). - CVE-2021-35559: Fixed excessive memory allocation in RTFReader (bsc#1191911). - CVE-2021-35561: Fixed excessive memory allocation in HashMap and HashSet (bsc#1191912). - CVE-2021-35564: Fixed certificates with end dates too far in the future can corrupt keystore (bsc#1191913). - CVE-2021-35565: Fixed loop in HttpsServer triggered during TLS session close (bsc#1191909). - CVE-2021-35586: Fixed excessive memory allocation in BMPImageReader (bsc#1191914). - CVE-2021-35588: Fixed incomplete validation of inner class references in ClassFileParser (bsc#1191905) - CVE-2021-35603: Fixed non-constant comparison during TLS handshakes (bsc#1191906).

Exploit probability Not scored
Published November 24, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:HPE Helion OpenStack 8 java-1_7_0-openjdk
SUSE:Linux Enterprise Server 12 SP2-BCL java-1_7_0-openjdk
SUSE:Linux Enterprise Server 12 SP3-BCL java-1_7_0-openjdk
SUSE:Linux Enterprise Server 12 SP3-LTSS java-1_7_0-openjdk
SUSE:Linux Enterprise Server 12 SP4-LTSS java-1_7_0-openjdk
SUSE:Linux Enterprise Server 12 SP5 java-1_7_0-openjdk
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 java-1_7_0-openjdk
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 java-1_7_0-openjdk
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 java-1_7_0-openjdk
SUSE:OpenStack Cloud 8 java-1_7_0-openjdk
SUSE:OpenStack Cloud 9 java-1_7_0-openjdk
SUSE:OpenStack Cloud Crowbar 8 java-1_7_0-openjdk
SUSE:OpenStack Cloud Crowbar 9 java-1_7_0-openjdk

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2021:3797-1

This update for java-1_7_0-openjdk fixes the following issues: Update to OpenJDK 7u321 (October 2021 CPU): - CVE-2021-35550: Fixed weak ciphers preferred over stronger ones for TLS (bsc#1191901). - CVE-2021-35556: Fixed excessive memory allocation in RTFParser (bsc#1191910). - CVE-2021-35559: Fixed excessive memory allocation in RTFReader (bsc#1191911). - CVE-2021-35561: Fixed excessive memory allocation in HashMap and HashSet (bsc#1191912). - CVE-2021-35564: Fixed certificates with end dates too far in the future can corrupt keystore (bsc#1191913). - CVE-2021-35565: Fixed loop in HttpsServer triggered during TLS session close (bsc#1191909). - CVE-2021-35586: Fixed excessive memory allocation in BMPImageReader (bsc#1191914). - CVE-2021-35588: Fixed incomplete validation of inner class references in ClassFileParser (bsc#1191905) - CVE-2021-35603: Fixed non-constant comparison during TLS handshakes (bsc#1191906).

View original source

05 / REFERENCES

Further evidence