Bug 1141784 - (CVE-2019-2745) VUL-0: CVE-2019-2745: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk: Issue inside Component Security
(CVE-2019-2745)
VUL-0: CVE-2019-2745: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk: ...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Fridrich Strba
Security Team bot
https://smash.suse.de/issue/237340/
CVSSv3:RedHat:CVE-2019-2745:5.1:(AV:L...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-17 07:51 UTC by Alexander Bergmann
Modified: 2019-09-04 06:07 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2019-07-17 07:51:00 UTC
Oracle Critical Patch Update Advisory - July 2019

CVE-2019-2745: Issue inside Component Security
- java-1_7_0-openjdk
- java-1_8_0-openjdk
- java-11-openjdk

References:
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html#AppendixJAVA
Comment 5 Swamp Workflow Management 2019-07-29 16:12:42 UTC
SUSE-SU-2019:2002-1: An update that solves 9 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1115375,1140461,1141780,1141781,1141782,1141783,1141784,1141785,1141787,1141788,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2818,CVE-2019-2821,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Basesystem 15 (src):    java-11-openjdk-11.0.4.0-3.33.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2019-07-30 19:13:08 UTC
SUSE-SU-2019:2021-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Legacy Software 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Legacy Software 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2019-07-31 16:11:19 UTC
SUSE-SU-2019:2028-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 1087082,1134297,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2018-3639,CVE-2019-2426,CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2019-08-01 19:13:52 UTC
SUSE-SU-2019:2036-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE OpenStack Cloud 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE OpenStack Cloud 7 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Desktop 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Enterprise Storage 5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Enterprise Storage 4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
HPE Helion Openstack 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2019-08-15 13:16:49 UTC
openSUSE-SU-2019:1916-1: An update that solves 9 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1115375,1140461,1141780,1141781,1141782,1141783,1141784,1141785,1141787,1141788,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2818,CVE-2019-2821,CVE-2019-7317
Sources used:
openSUSE Leap 15.1 (src):    java-11-openjdk-11.0.4.0-lp151.3.6.1
openSUSE Leap 15.0 (src):    java-11-openjdk-11.0.4.0-lp150.2.25.1
Comment 10 Swamp Workflow Management 2019-08-15 13:23:24 UTC
openSUSE-SU-2019:1912-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
openSUSE Leap 15.1 (src):    java-1_8_0-openjdk-1.8.0.222-lp151.2.3.1
openSUSE Leap 15.0 (src):    java-1_8_0-openjdk-1.8.0.222-lp150.2.19.1
Comment 11 Swamp Workflow Management 2019-08-16 22:12:26 UTC
SUSE-SU-2019:2036-2: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Enterprise Storage 5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Marcus Meissner 2019-09-04 06:07:50 UTC
released