Bug 1141786 - (CVE-2019-2842) VUL-0: CVE-2019-2842: java-1_8_0-openjdk: Issue inside Component JCE
(CVE-2019-2842)
VUL-0: CVE-2019-2842: java-1_8_0-openjdk: Issue inside Component JCE
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Fridrich Strba
Security Team bot
https://smash.suse.de/issue/237345/
CVSSv3:RedHat:CVE-2019-2842:3.7:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-17 07:51 UTC by Alexander Bergmann
Modified: 2019-09-04 06:04 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2019-07-17 07:51:05 UTC
Oracle Critical Patch Update Advisory - July 2019

CVE-2019-2842: Issue inside Component JCE
- java-1_8_0-openjdk

References:
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html#AppendixJAVA
Comment 2 Swamp Workflow Management 2019-07-30 19:13:22 UTC
SUSE-SU-2019:2021-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Legacy Software 15-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2
SUSE Linux Enterprise Module for Legacy Software 15 (src):    java-1_8_0-openjdk-1.8.0.222-3.24.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 3 Swamp Workflow Management 2019-07-31 16:11:33 UTC
SUSE-SU-2019:2028-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 1087082,1134297,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2018-3639,CVE-2019-2426,CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_7_0-openjdk-1.7.0.231-43.27.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 4 Swamp Workflow Management 2019-08-01 19:14:05 UTC
SUSE-SU-2019:2036-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE OpenStack Cloud 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE OpenStack Cloud 7 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP3-BCL (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP2-BCL (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Desktop 12-SP5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Linux Enterprise Desktop 12-SP4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Enterprise Storage 5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
SUSE Enterprise Storage 4 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2
HPE Helion Openstack 8 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2019-08-15 13:23:39 UTC
openSUSE-SU-2019:1912-1: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
openSUSE Leap 15.1 (src):    java-1_8_0-openjdk-1.8.0.222-lp151.2.3.1
openSUSE Leap 15.0 (src):    java-1_8_0-openjdk-1.8.0.222-lp150.2.19.1
Comment 6 Swamp Workflow Management 2019-08-16 22:12:40 UTC
SUSE-SU-2019:2036-2: An update that solves 8 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1115375,1141780,1141782,1141783,1141784,1141785,1141786,1141787,1141789
CVE References: CVE-2019-2745,CVE-2019-2762,CVE-2019-2766,CVE-2019-2769,CVE-2019-2786,CVE-2019-2816,CVE-2019-2842,CVE-2019-7317
Sources used:
SUSE Enterprise Storage 5 (src):    java-1_8_0-openjdk-1.8.0.222-27.35.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Marcus Meissner 2019-09-04 06:04:59 UTC
released