Security update for java-1_8_0-openjdk
This update for java-1_8_0-openjdk fixes the following issues: - Updated to version jdk8u345 (icedtea-3.24.0) - CVE-2022-21540: Fixed a potential Java sandbox bypass (bsc#1201694). - CVE-2022-21541: Fixed a potential Java sandbox bypass (bsc#1201692). - CVE-2022-34169: Fixed an issue where arbitrary bytecode could be executed via a malicious stylesheet (bsc#1201684). - Non-security fixes: - Allowed for customization of PKCS12 keystores (bsc#1195163).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for java-1_8_0-openjdk fixes the following issues: - Updated to version jdk8u345 (icedtea-3.24.0) - CVE-2022-21540: Fixed a potential Java sandbox bypass (bsc#1201694). - CVE-2022-21541: Fixed a potential Java sandbox bypass (bsc#1201692). - CVE-2022-34169: Fixed an issue where arbitrary bytecode could be executed via a malicious stylesheet (bsc#1201684). - Non-security fixes: - Allowed for customization of PKCS12 keystores (bsc#1195163).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1195163
- https://bugzilla.suse.com/1201684
- https://bugzilla.suse.com/1201692
- https://bugzilla.suse.com/1201694
- https://www.suse.com/security/cve/CVE-2022-21540
- https://www.suse.com/security/cve/CVE-2022-21541
- https://www.suse.com/security/cve/CVE-2022-34169
- https://www.suse.com/support/update/announcement/2022/suse-su-20222819-1/