Bug 1134297 - (CVE-2019-2426) VUL-0: CVE-2019-2426: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk: Improve web server connections (subcomponent: Networking)
(CVE-2019-2426)
VUL-0: CVE-2019-2426: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk: ...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-05-07 10:13 UTC by Alexander Bergmann
Modified: 2019-09-04 06:10 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2019-05-07 10:13:52 UTC
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-2426

Vulnerability in the Java SE component of Oracle Java SE (subcomponent:
Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and
11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise Java SE. Successful attacks of this vulnerability can result in
unauthorized read access to a subset of Java SE accessible data. Note: This
vulnerability applies to Java deployments, typically in clients running
sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8),
that load and run untrusted code (e.g., code that comes from the internet) and
rely on the Java sandbox for security. This vulnerability can also be exploited
by using APIs in the specified Component, e.g., through a web service which
supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Confidentiality impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Comment 1 Swamp Workflow Management 2019-05-31 13:26:44 UTC
SUSE-SU-2019:1392-1: An update that fixes 6 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1122293,1122299,1132728,1132729,1132732,1134297
CVE References: CVE-2018-11212,CVE-2019-2422,CVE-2019-2426,CVE-2019-2602,CVE-2019-2684,CVE-2019-2698
Sources used:
SUSE OpenStack Cloud 7 (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Server 12-SP3 (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Server 12-LTSS (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1
SUSE Enterprise Storage 4 (src):    java-1_7_0-openjdk-1.7.0.221-43.22.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 2 Swamp Workflow Management 2019-06-03 13:17:49 UTC
openSUSE-SU-2019:1500-1: An update that fixes 6 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1122293,1122299,1132728,1132729,1132732,1134297
CVE References: CVE-2018-11212,CVE-2019-2422,CVE-2019-2426,CVE-2019-2602,CVE-2019-2684,CVE-2019-2698
Sources used:
openSUSE Leap 42.3 (src):    java-1_7_0-openjdk-1.7.0.221-57.1, java-1_7_0-openjdk-bootstrap-1.7.0.221-57.1
Comment 3 Swamp Workflow Management 2019-07-31 16:10:48 UTC
SUSE-SU-2019:2028-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 1087082,1134297,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2018-3639,CVE-2019-2426,CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 4 Marcus Meissner 2019-09-04 06:10:58 UTC
released