Bug 935540 - VUL-1: IBM Java: The logjam Attack
VUL-1: IBM Java: The logjam Attack
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
maint:running:62187:important maint:p...
:
Depends on: CVE-2015-4000
Blocks:
  Show dependency treegraph
 
Reported: 2015-06-22 06:02 UTC by Marcus Meissner
Modified: 2019-08-29 22:47 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2015-06-22 06:02:39 UTC
+++ This bug was initially created as a clone of Bug #931600 +++

IBM has released a full round of IBM Java updates to address the Logjam
attack CVE-2015-4000

http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_June_2015

5.0 SR16-FP11 
6 SR16-FP5 
6R1 SR8-FP5 	
7 SR9-FP1 
7R1 SR3-FP1 	
8 SR1-FP1
Comment 2 Swamp Workflow Management 2015-06-22 22:00:16 UTC
bugbot adjusting priority
Comment 4 Swamp Workflow Management 2015-07-03 11:19:13 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2015-07-10.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/62187
Comment 6 Johannes Segitz 2015-07-08 13:18:51 UTC
we will wait with the update for the next regular release
Comment 12 Swamp Workflow Management 2015-07-31 14:09:02 UTC
SUSE-SU-2015:1329-1: An update that fixes 20 vulnerabilities is now available.

Category: security (important)
Bug References: 935540,938895
CVE References: CVE-2015-1931,CVE-2015-2590,CVE-2015-2601,CVE-2015-2613,CVE-2015-2619,CVE-2015-2621,CVE-2015-2625,CVE-2015-2632,CVE-2015-2637,CVE-2015-2638,CVE-2015-2664,CVE-2015-2808,CVE-2015-4000,CVE-2015-4729,CVE-2015-4731,CVE-2015-4732,CVE-2015-4733,CVE-2015-4748,CVE-2015-4749,CVE-2015-4760
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    java-1_7_1-ibm-1.7.1_sr3.10-3.1
SUSE Linux Enterprise Server 11-SP4 (src):    java-1_7_1-ibm-1.7.1_sr3.10-3.1
Comment 13 Swamp Workflow Management 2015-07-31 14:11:15 UTC
SUSE-SU-2015:1331-1: An update that fixes 20 vulnerabilities is now available.

Category: security (important)
Bug References: 935540,938895
CVE References: CVE-2015-1931,CVE-2015-2590,CVE-2015-2601,CVE-2015-2613,CVE-2015-2619,CVE-2015-2621,CVE-2015-2625,CVE-2015-2632,CVE-2015-2637,CVE-2015-2638,CVE-2015-2664,CVE-2015-2808,CVE-2015-4000,CVE-2015-4729,CVE-2015-4731,CVE-2015-4732,CVE-2015-4733,CVE-2015-4748,CVE-2015-4749,CVE-2015-4760
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    java-1_7_1-ibm-1.7.1_sr3.10-14.1
SUSE Linux Enterprise Server 12 (src):    java-1_7_1-ibm-1.7.1_sr3.10-14.1
Comment 14 LTC BugProxy 2015-08-04 06:04:09 UTC
------- Comment From hannsj_uhl@de.ibm.com 2015-08-03 09:12 EDT-------
.

------- Comment From hannsj_uhl@de.ibm.com 2015-08-04 05:53 EDT-------
.
Comment 15 Swamp Workflow Management 2015-08-05 09:08:55 UTC
SUSE-SU-2015:1345-1: An update that fixes 17 vulnerabilities is now available.

Category: security (important)
Bug References: 935540,936844,938895
CVE References: CVE-2015-1931,CVE-2015-2590,CVE-2015-2601,CVE-2015-2621,CVE-2015-2625,CVE-2015-2632,CVE-2015-2637,CVE-2015-2638,CVE-2015-2664,CVE-2015-2808,CVE-2015-4000,CVE-2015-4731,CVE-2015-4732,CVE-2015-4733,CVE-2015-4748,CVE-2015-4749,CVE-2015-4760
Sources used:
SUSE Linux Enterprise Module for Legacy Software 12 (src):    java-1_6_0-ibm-1.6.0_sr16.7-22.2
Comment 16 Swamp Workflow Management 2015-08-12 16:09:39 UTC
SUSE-SU-2015:1375-1: An update that fixes 21 vulnerabilities is now available.

Category: security (important)
Bug References: 935540,938895
CVE References: CVE-2015-0192,CVE-2015-1931,CVE-2015-2590,CVE-2015-2601,CVE-2015-2613,CVE-2015-2619,CVE-2015-2621,CVE-2015-2625,CVE-2015-2632,CVE-2015-2637,CVE-2015-2638,CVE-2015-2664,CVE-2015-2808,CVE-2015-4000,CVE-2015-4729,CVE-2015-4731,CVE-2015-4732,CVE-2015-4733,CVE-2015-4748,CVE-2015-4749,CVE-2015-4760
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP3 (src):    java-1_7_0-ibm-1.7.0_sr9.10-9.1
SUSE Linux Enterprise Server for VMWare 11-SP3 (src):    java-1_7_0-ibm-1.7.0_sr9.10-9.1
SUSE Linux Enterprise Server 11-SP3 (src):    java-1_7_0-ibm-1.7.0_sr9.10-9.1
SUSE Linux Enterprise Server 11-SP2-LTSS (src):    java-1_7_0-ibm-1.7.0_sr9.10-9.1
Comment 18 Marcus Meissner 2015-09-08 10:48:36 UTC
released, reorder the dep chain
Comment 19 Swamp Workflow Management 2015-09-08 11:10:16 UTC
SUSE-SU-2015:1509-1: An update that fixes 17 vulnerabilities is now available.

Category: security (important)
Bug References: 935540,936844,938895,941939
CVE References: CVE-2015-1931,CVE-2015-2590,CVE-2015-2601,CVE-2015-2621,CVE-2015-2625,CVE-2015-2632,CVE-2015-2637,CVE-2015-2638,CVE-2015-2664,CVE-2015-2808,CVE-2015-4000,CVE-2015-4731,CVE-2015-4732,CVE-2015-4733,CVE-2015-4748,CVE-2015-4749,CVE-2015-4760
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP3 (src):    java-1_6_0-ibm-1.6.0_sr16.7-10.1
SUSE Linux Enterprise Server for VMWare 11-SP3 (src):    java-1_6_0-ibm-1.6.0_sr16.7-10.1
SUSE Linux Enterprise Server 11-SP3 (src):    java-1_6_0-ibm-1.6.0_sr16.7-10.1
SUSE Linux Enterprise Server 11-SP2-LTSS (src):    java-1_6_0-ibm-1.6.0_sr16.7-10.1
SUSE Linux Enterprise Server 11-SP1-LTSS (src):    java-1_6_0-ibm-1.6.0_sr16.7-10.1