SUSE-SU-2017:0839-1
Dashboard / Vulnerabilities / SUSE-SU-2017:0839-1
SUSE-SU-2017:0839-1
Summary: Security update for java-1_8_0-ibm
Details: This update for java-1_8_0-ibm fixes the following issues: Security issue fixed: - CVE-2016-2183: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a 'Sweet32' attack. (bsc#1027038) Bugfixes: - Require the main pkg in post phase of devel (bsc#1025506)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20170839-1/, https://bugzilla.suse.com/1025506, https://bugzilla.suse.com/1027038, https://www.suse.com/security/cve/CVE-2016-2183
Affected packages
Package
Name: java-1_8_0-ibm
Purl: pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
