Bug 1141783 (CVE-2019-2769)

Summary: VUL-0: CVE-2019-2769: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk: Issue inside Component Utilities
Product: [Novell Products] SUSE Security Incidents Reporter: Alexander Bergmann <abergmann>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: meissner
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/237339/
Whiteboard: CVSSv3:RedHat:CVE-2019-2769:5.3:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVSSv3:SUSE:CVE-2019-2769:5.3:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVSSv3:UNK(Oracle):CVE-2019-2769:5.3:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) CVSSv2:NVD:CVE-2019-2769:5.0:(AV:N/AC:L/Au:N/C:N/I:N/A:P) CVSSv3:NVD:CVE-2019-2769:5.3:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexander Bergmann 2019-07-17 07:50:56 UTC
Oracle Critical Patch Update Advisory - July 2019

CVE-2019-2769: Issue inside Component Utilities
- java-1_7_0-openjdk
- java-1_8_0-openjdk
- java-11-openjdk

References:
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html#AppendixJAVA
Comment 5 Swamp Workflow Management 2019-07-29 16:12:35 UTC
SUSE-SU-2019:2002-1: An update that solves 9 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1115375,1140461,1141780,1141781,1141782,1141783,1141784,1141785,1141787,1141788,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2818,CVE-2019-2821,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Basesystem 15 (src):    java-11-openjdk-11.0.4.0-3.33.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2019-07-30 19:13:01 UTC
SUSE-SU-2019:2021-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Legacy Software 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Legacy Software 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2019-07-31 16:11:11 UTC
SUSE-SU-2019:2028-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 1087082,1134297,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2018-3639,CVE-2019-2426,CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2019-08-01 19:13:45 UTC
SUSE-SU-2019:2036-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE OpenStack Cloud 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE OpenStack Cloud 7 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Desktop 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Enterprise Storage 5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Enterprise Storage 4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
HPE Helion Openstack 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2019-08-15 13:16:41 UTC
openSUSE-SU-2019:1916-1: An update that solves 9 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1115375,1140461,1141780,1141781,1141782,1141783,1141784,1141785,1141787,1141788,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2818,CVE-2019-2821,CVE-2019-7317
Sources used:
openSUSE Leap 15.1 (src):    java-11-openjdk-11.0.4.0-lp151.3.6.1
openSUSE Leap 15.0 (src):    java-11-openjdk-11.0.4.0-lp150.2.25.1
Comment 10 Swamp Workflow Management 2019-08-15 13:23:17 UTC
openSUSE-SU-2019:1912-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
openSUSE Leap 15.1 (src):    java-1_8_0-openjdk-1.8.0.222-lp151.2.3.1
openSUSE Leap 15.0 (src):    java-1_8_0-openjdk-1.8.0.222-lp150.2.19.1
Comment 11 Swamp Workflow Management 2019-08-16 22:12:19 UTC
SUSE-SU-2019:2036-2: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Enterprise Storage 5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Swamp Workflow Management 2019-09-04 11:06:37 UTC
SUSE-SU-2019:14160-1: An update that fixes 8 vulnerabilities is now available.

Category: security (important)
Bug References: 1141780,1141782,1141783,1141785,1141789,1147021
CVE References: CVE-2019-11771,CVE-2019-11775,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    java-1_7_1-ibm-1.7.1_sr4.50-26.44.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Swamp Workflow Management 2019-09-04 19:14:04 UTC
SUSE-SU-2019:2291-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1122292,1122299,1141780,1141782,1141783,1141785,1141787,1141789,1147021
CVE References: CVE-2018-11212,CVE-2019-11771,CVE-2019-11772,CVE-2019-11775,CVE-2019-2449,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-1_8_0-ibm-1.8.0_sr5.40-3.24.1
SUSE Linux Enterprise Module for Legacy Software 15-SP1 (src):    java-1_8_0-ibm-1.8.0_sr5.40-3.24.1
SUSE Linux Enterprise Module for Legacy Software 15 (src):    java-1_8_0-ibm-1.8.0_sr5.40-3.24.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Swamp Workflow Management 2019-09-09 16:12:28 UTC
SUSE-SU-2019:2336-1: An update that fixes 8 vulnerabilities is now available.

Category: security (important)
Bug References: 1141780,1141782,1141783,1141785,1141789,1147021
CVE References: CVE-2019-11771,CVE-2019-11775,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE OpenStack Cloud 8 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE OpenStack Cloud 7 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Enterprise Storage 5 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Enterprise Storage 4 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
HPE Helion Openstack 8 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 19 Swamp Workflow Management 2019-09-12 19:48:42 UTC
SUSE-SU-2019:2371-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1122292,1122299,1141780,1141782,1141783,1141785,1141787,1141789,1147021
CVE References: CVE-2018-11212,CVE-2019-11771,CVE-2019-11772,CVE-2019-11775,CVE-2019-2449,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE OpenStack Cloud 8 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE OpenStack Cloud 7 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Enterprise Storage 5 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Enterprise Storage 4 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
HPE Helion Openstack 8 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 20 Swamp Workflow Management 2019-10-04 13:12:06 UTC
SUSE-SU-2019:14188-1: An update that fixes 8 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1141782,1141783,1141789,1147021
CVE References: CVE-2019-11771,CVE-2019-11775,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    java-1_7_0-ibm-1.7.0_sr10.50-65.42.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 21 Fridrich Strba 2019-10-07 10:41:39 UTC
This has been released
Comment 22 Marcus Meissner 2019-10-07 11:16:24 UTC
released