Bug 1141782 - (CVE-2019-2762) VUL-0: CVE-2019-2762: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk: Issue inside Component Utilities
(CVE-2019-2762)
VUL-0: CVE-2019-2762: java-1_7_0-openjdk,java-1_8_0-openjdk,java-11-openjdk: ...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/237309/
CVSSv3:RedHat:CVE-2019-2762:5.3:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-17 07:50 UTC by Alexander Bergmann
Modified: 2019-10-07 11:14 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2019-07-17 07:50:53 UTC
Oracle Critical Patch Update Advisory - July 2019

CVE-2019-2762: Issue inside Component Utilities
- java-1_7_0-openjdk
- java-1_8_0-openjdk
- java-11-openjdk

References:
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html#AppendixJAVA
Comment 5 Swamp Workflow Management 2019-07-29 16:12:29 UTC
SUSE-SU-2019:2002-1: An update that solves 9 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1115375,1140461,1141780,1141781,1141782,1141783,1141784,1141785,1141787,1141788,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2818,CVE-2019-2821,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    java-11-openjdk-11.0.4.0-3.33.1
SUSE Linux Enterprise Module for Basesystem 15 (src):    java-11-openjdk-11.0.4.0-3.33.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2019-07-30 19:12:54 UTC
SUSE-SU-2019:2021-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Legacy Software 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Legacy Software 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2019-07-31 16:11:03 UTC
SUSE-SU-2019:2028-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 1087082,1134297,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2018-3639,CVE-2019-2426,CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2019-08-01 19:13:39 UTC
SUSE-SU-2019:2036-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE OpenStack Cloud 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE OpenStack Cloud 7 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Desktop 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Enterprise Storage 5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Enterprise Storage 4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
HPE Helion Openstack 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2019-08-15 13:16:33 UTC
openSUSE-SU-2019:1916-1: An update that solves 9 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1115375,1140461,1141780,1141781,1141782,1141783,1141784,1141785,1141787,1141788,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2818,CVE-2019-2821,CVE-2019-7317
Sources used:
openSUSE Leap 15.1 (src):    java-11-openjdk-11.0.4.0-lp151.3.6.1
openSUSE Leap 15.0 (src):    java-11-openjdk-11.0.4.0-lp150.2.25.1
Comment 10 Swamp Workflow Management 2019-08-15 13:23:09 UTC
openSUSE-SU-2019:1912-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
openSUSE Leap 15.1 (src):    java-1_8_0-openjdk-1.8.0.222-lp151.2.3.1
openSUSE Leap 15.0 (src):    java-1_8_0-openjdk-1.8.0.222-lp150.2.19.1
Comment 11 Swamp Workflow Management 2019-08-16 22:12:11 UTC
SUSE-SU-2019:2036-2: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Enterprise Storage 5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Swamp Workflow Management 2019-09-04 11:06:30 UTC
SUSE-SU-2019:14160-1: An update that fixes 8 vulnerabilities is now available.

Category: security (important)
Bug References: 1141780,1141782,1141783,1141785,1141789,1147021
CVE References: CVE-2019-11771,CVE-2019-11775,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    java-1_7_1-ibm-1.7.1_sr4.50-26.44.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Swamp Workflow Management 2019-09-04 19:13:56 UTC
SUSE-SU-2019:2291-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1122292,1122299,1141780,1141782,1141783,1141785,1141787,1141789,1147021
CVE References: CVE-2018-11212,CVE-2019-11771,CVE-2019-11772,CVE-2019-11775,CVE-2019-2449,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-1_8_0-ibm-1.8.0_sr5.40-3.24.1
SUSE Linux Enterprise Module for Legacy Software 15-SP1 (src):    java-1_8_0-ibm-1.8.0_sr5.40-3.24.1
SUSE Linux Enterprise Module for Legacy Software 15 (src):    java-1_8_0-ibm-1.8.0_sr5.40-3.24.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Swamp Workflow Management 2019-09-09 16:12:21 UTC
SUSE-SU-2019:2336-1: An update that fixes 8 vulnerabilities is now available.

Category: security (important)
Bug References: 1141780,1141782,1141783,1141785,1141789,1147021
CVE References: CVE-2019-11771,CVE-2019-11775,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE OpenStack Cloud 8 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE OpenStack Cloud 7 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Enterprise Storage 5 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
SUSE Enterprise Storage 4 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1
HPE Helion Openstack 8 (src):    java-1_7_1-ibm-1.7.1_sr4.50-38.41.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 19 Swamp Workflow Management 2019-09-12 19:48:36 UTC
SUSE-SU-2019:2371-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1122292,1122299,1141780,1141782,1141783,1141785,1141787,1141789,1147021
CVE References: CVE-2018-11212,CVE-2019-11771,CVE-2019-11772,CVE-2019-11775,CVE-2019-2449,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE OpenStack Cloud 8 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE OpenStack Cloud 7 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Enterprise Storage 5 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
SUSE Enterprise Storage 4 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1
HPE Helion Openstack 8 (src):    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 20 Swamp Workflow Management 2019-10-04 13:11:58 UTC
SUSE-SU-2019:14188-1: An update that fixes 8 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1141782,1141783,1141789,1147021
CVE References: CVE-2019-11771,CVE-2019-11775,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2816,CVE-2019-4473,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    java-1_7_0-ibm-1.7.0_sr10.50-65.42.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 21 Fridrich Strba 2019-10-07 10:06:01 UTC
Released
Comment 22 Marcus Meissner 2019-10-07 11:14:53 UTC
relkeased