SCIENTIFIC-LINUX-ERRATA Archives

July 2016

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Scott Reid <[log in to unmask]>
Reply To:
Date:
Wed, 20 Jul 2016 20:18:35 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (83 lines)
Synopsis:          Critical: java-1.8.0-openjdk security update
Advisory ID:       SLSA-2016:1458-1
Issue Date:        2016-07-20
CVE Numbers:       CVE-2016-3606
                   CVE-2016-3598
                   CVE-2016-3587
                   CVE-2016-3610
                   CVE-2016-3500
                   CVE-2016-3508
                   CVE-2016-3458
                   CVE-2016-3550
--

Security Fix(es):

* Multiple flaws were discovered in the Hotspot and Libraries components
in OpenJDK. An untrusted Java application or applet could use these flaws
to completely bypass Java sandbox restrictions. (CVE-2016-3606,
CVE-2016-3587, CVE-2016-3598, CVE-2016-3610)

* Multiple denial of service flaws were found in the JAXP component in
OpenJDK. A specially crafted XML file could cause a Java application using
JAXP to consume an excessive amount of CPU and memory when parsed.
(CVE-2016-3500, CVE-2016-3508)

* Multiple flaws were found in the CORBA and Hotsport components in
OpenJDK. An untrusted Java application or applet could use these flaws to
bypass certain Java sandbox restrictions. (CVE-2016-3458, CVE-2016-3550)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.
--

SL6
  x86_64
    java-1.8.0-openjdk-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-debuginfo-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-headless-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-debug-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-demo-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-demo-debug-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-devel-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-devel-debug-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-headless-debug-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-src-1.8.0.101-3.b13.el6_8.x86_64.rpm
    java-1.8.0-openjdk-src-debug-1.8.0.101-3.b13.el6_8.x86_64.rpm
  i386
    java-1.8.0-openjdk-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-debuginfo-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-headless-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-debug-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-demo-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-demo-debug-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-devel-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-devel-debug-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-headless-debug-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-src-1.8.0.101-3.b13.el6_8.i686.rpm
    java-1.8.0-openjdk-src-debug-1.8.0.101-3.b13.el6_8.i686.rpm
  noarch
    java-1.8.0-openjdk-javadoc-1.8.0.101-3.b13.el6_8.noarch.rpm
    java-1.8.0-openjdk-javadoc-debug-1.8.0.101-3.b13.el6_8.noarch.rpm
SL7
  x86_64
    java-1.8.0-openjdk-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-debuginfo-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-headless-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-accessibility-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-accessibility-debug-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-debug-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-demo-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-demo-debug-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-devel-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-devel-debug-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-headless-debug-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-src-1.8.0.101-3.b13.el7_2.x86_64.rpm
    java-1.8.0-openjdk-src-debug-1.8.0.101-3.b13.el7_2.x86_64.rpm
  noarch
    java-1.8.0-openjdk-javadoc-1.8.0.101-3.b13.el7_2.noarch.rpm
    java-1.8.0-openjdk-javadoc-debug-1.8.0.101-3.b13.el7_2.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2