SUSE-SU-2017:2175-1

    Dashboard / Vulnerabilities / SUSE-SU-2017:2175-1

    SUSE-SU-2017:2175-1

    Published: 16 Aug 2017Last Modified: 4 Feb 2026

    Summary: Security update for java-1_8_0-openjdk

    Details: This java-1_8_0-openjdk update to version jdk8u141 (icedtea 3.5.0) fixes the following issues: Security issues fixed: - CVE-2017-10053: Improved image post-processing steps (bsc#1049305) - CVE-2017-10067: Additional jar validation steps (bsc#1049306) - CVE-2017-10074: Image conversion improvements (bsc#1049307) - CVE-2017-10078: Better script accessibility for JavaScript (bsc#1049308) - CVE-2017-10081: Right parenthesis issue (bsc#1049309) - CVE-2017-10086: Unspecified vulnerability in subcomponent JavaFX (bsc#1049310) - CVE-2017-10087: Better Thread Pool execution (bsc#1049311) - CVE-2017-10089: Service Registration Lifecycle (bsc#1049312) - CVE-2017-10090: Better handling of channel groups (bsc#1049313) - CVE-2017-10096: Transform Transformer Exceptions (bsc#1049314) - CVE-2017-10101: Better reading of text catalogs (bsc#1049315) - CVE-2017-10102: Improved garbage collection (bsc#1049316) - CVE-2017-10105: Unspecified vulnerability in subcomponent deployment (bsc#1049317) - CVE-2017-10107: Less Active Activations (bsc#1049318) - CVE-2017-10108: Better naming attribution (bsc#1049319) - CVE-2017-10109: Better sourcing of code (bsc#1049320) - CVE-2017-10110: Better image fetching (bsc#1049321) - CVE-2017-10111: Rearrange MethodHandle arrangements (bsc#1049322) - CVE-2017-10114: Unspecified vulnerability in subcomponent JavaFX (bsc#1049323) - CVE-2017-10115: Higher quality DSA operations (bsc#1049324) - CVE-2017-10116: Proper directory lookup processing (bsc#1049325) - CVE-2017-10118: Higher quality ECDSA operations (bsc#1049326) - CVE-2017-10125: Unspecified vulnerability in subcomponent deployment (bsc#1049327) - CVE-2017-10135: Better handling of PKCS8 material (bsc#1049328) - CVE-2017-10176: Additional elliptic curve support (bsc#1049329) - CVE-2017-10193: Improve algorithm constraints implementation (bsc#1049330) - CVE-2017-10198: Clear certificate chain connections (bsc#1049331) - CVE-2017-10243: Unspecified vulnerability in subcomponent JAX-WS (bsc#1049332) Bug fixes: - Check registry registration location - Improved certificate processing - JMX diagnostic improvements - Update to libpng 1.6.28 - Import of OpenJDK 8 u141 build 15 (bsc#1049302) New features: - Support using RSAandMGF1 with the SHA hash algorithms in the PKCS11 provider

    References: https://www.suse.com/support/update/announcement/2017/suse-su-20172175-1/, https://bugzilla.suse.com/1049302, https://bugzilla.suse.com/1049305, https://bugzilla.suse.com/1049306, https://bugzilla.suse.com/1049307, https://bugzilla.suse.com/1049308, https://bugzilla.suse.com/1049309, https://bugzilla.suse.com/1049310, https://bugzilla.suse.com/1049311, https://bugzilla.suse.com/1049312, https://bugzilla.suse.com/1049313, https://bugzilla.suse.com/1049314, https://bugzilla.suse.com/1049315, https://bugzilla.suse.com/1049316, https://bugzilla.suse.com/1049317, https://bugzilla.suse.com/1049318, https://bugzilla.suse.com/1049319, https://bugzilla.suse.com/1049320, https://bugzilla.suse.com/1049321, https://bugzilla.suse.com/1049322, https://bugzilla.suse.com/1049323, https://bugzilla.suse.com/1049324, https://bugzilla.suse.com/1049325, https://bugzilla.suse.com/1049326, https://bugzilla.suse.com/1049327, https://bugzilla.suse.com/1049328, https://bugzilla.suse.com/1049329, https://bugzilla.suse.com/1049330, https://bugzilla.suse.com/1049331, https://bugzilla.suse.com/1049332, https://www.suse.com/security/cve/CVE-2017-10053, https://www.suse.com/security/cve/CVE-2017-10067, https://www.suse.com/security/cve/CVE-2017-10074, https://www.suse.com/security/cve/CVE-2017-10078, https://www.suse.com/security/cve/CVE-2017-10081, https://www.suse.com/security/cve/CVE-2017-10086, https://www.suse.com/security/cve/CVE-2017-10087, https://www.suse.com/security/cve/CVE-2017-10089, https://www.suse.com/security/cve/CVE-2017-10090, https://www.suse.com/security/cve/CVE-2017-10096, https://www.suse.com/security/cve/CVE-2017-10101, https://www.suse.com/security/cve/CVE-2017-10102, https://www.suse.com/security/cve/CVE-2017-10105, https://www.suse.com/security/cve/CVE-2017-10107, https://www.suse.com/security/cve/CVE-2017-10108, https://www.suse.com/security/cve/CVE-2017-10109, https://www.suse.com/security/cve/CVE-2017-10110, https://www.suse.com/security/cve/CVE-2017-10111, https://www.suse.com/security/cve/CVE-2017-10114, https://www.suse.com/security/cve/CVE-2017-10115, https://www.suse.com/security/cve/CVE-2017-10116, https://www.suse.com/security/cve/CVE-2017-10118, https://www.suse.com/security/cve/CVE-2017-10125, https://www.suse.com/security/cve/CVE-2017-10135, https://www.suse.com/security/cve/CVE-2017-10176, https://www.suse.com/security/cve/CVE-2017-10193, https://www.suse.com/security/cve/CVE-2017-10198, https://www.suse.com/security/cve/CVE-2017-10243

    Affected packages

    Package

    Name: java-1_8_0-openjdk

    Purl: pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20OpenStack%20Cloud%206

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.8.0.144-27.5.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High