{"affected":[{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 6","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20OpenStack%20Cloud%206"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP3","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP1","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP1-LTSS","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP3","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.161-43.7.6","java-1_7_0-openjdk-demo":"1.7.0.161-43.7.6","java-1_7_0-openjdk-devel":"1.7.0.161-43.7.6","java-1_7_0-openjdk-headless":"1.7.0.161-43.7.6"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.161-43.7.6"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for java-1_7_0-openjdk fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2017-10356: Fix issue inside subcomponent Security (bsc#1064084).\n- CVE-2017-10274: Fix issue inside subcomponent Smart Card IO (bsc#1064071).\n- CVE-2017-10281: Fix issue inside subcomponent Serialization (bsc#1064072).\n- CVE-2017-10285: Fix issue inside subcomponent RMI (bsc#1064073).\n- CVE-2017-10295: Fix issue inside subcomponent Networking (bsc#1064075).\n- CVE-2017-10388: Fix issue inside subcomponent Libraries (bsc#1064086).\n- CVE-2017-10346: Fix issue inside subcomponent Hotspot (bsc#1064078).\n- CVE-2017-10350: Fix issue inside subcomponent JAX-WS (bsc#1064082).\n- CVE-2017-10347: Fix issue inside subcomponent Serialization (bsc#1064079).\n- CVE-2017-10349: Fix issue inside subcomponent JAXP (bsc#1064081).\n- CVE-2017-10345: Fix issue inside subcomponent Serialization (bsc#1064077).\n- CVE-2017-10348: Fix issue inside subcomponent Libraries (bsc#1064080).\n- CVE-2017-10357: Fix issue inside subcomponent Serialization (bsc#1064085).\n- CVE-2017-10355: Fix issue inside subcomponent Networking (bsc#1064083).\n- CVE-2017-10102: Fix incorrect handling of references in DGC (bsc#1049316).\n- CVE-2017-10053: Fix reading of unprocessed image data in JPEGImageReader (bsc#1049305).\n- CVE-2017-10067: Fix JAR verifier incorrect handling of missing digest (bsc#1049306).\n- CVE-2017-10081: Fix incorrect bracket processing in function signature handling (bsc#1049309).\n- CVE-2017-10087: Fix insufficient access control checks in ThreadPoolExecutor (bsc#1049311).\n- CVE-2017-10089: Fix insufficient access control checks in ServiceRegistry (bsc#1049312).\n- CVE-2017-10090: Fix insufficient access control checks in AsynchronousChannelGroupImpl (bsc#1049313).\n- CVE-2017-10096: Fix insufficient access control checks in XML transformations (bsc#1049314).\n- CVE-2017-10101: Fix unrestricted access to com.sun.org.apache.xml.internal.resolver (bsc#1049315).\n- CVE-2017-10107: Fix insufficient access control checks in ActivationID (bsc#1049318).\n- CVE-2017-10074: Fix integer overflows in range check loop predicates (bsc#1049307).\n- CVE-2017-10110: Fix insufficient access control checks in ImageWatched (bsc#1049321).\n- CVE-2017-10108: Fix unbounded memory allocation in BasicAttribute deserialization (bsc#1049319).\n- CVE-2017-10109: Fix unbounded memory allocation in CodeSource deserialization (bsc#1049320).\n- CVE-2017-10115: Fix unspecified vulnerability in subcomponent JCE (bsc#1049324).\n- CVE-2017-10118: Fix ECDSA implementation timing attack (bsc#1049326).\n- CVE-2017-10116: Fix LDAPCertStore following referrals to non-LDAP URL (bsc#1049325).\n- CVE-2017-10135: Fix PKCS#8 implementation timing attack (bsc#1049328).\n- CVE-2017-10176: Fix incorrect handling of certain EC points (bsc#1049329).\n- CVE-2017-10074: Fix integer overflows in range check loop predicates (bsc#1049307).\n- CVE-2017-10074: Fix integer overflows in range check loop predicates (bsc#1049307).\n- CVE-2017-10111: Fix checks in LambdaFormEditor (bsc#1049322).\n- CVE-2017-10243: Fix unspecified vulnerability in subcomponent JAX-WS (bsc#1049332).\n- CVE-2017-10125: Fix unspecified vulnerability in subcomponent deployment (bsc#1049327).\n- CVE-2017-10114: Fix unspecified vulnerability in subcomponent JavaFX (bsc#1049323).\n- CVE-2017-10105: Fix unspecified vulnerability in subcomponent deployment (bsc#1049317).\n- CVE-2017-10086: Fix unspecified in subcomponent JavaFX (bsc#1049310).\n- CVE-2017-10198: Fix incorrect enforcement of certificate path restrictions (bsc#1049331).\n- CVE-2017-10193: Fix incorrect key size constraint check (bsc#1049330).\n\nBug fixes:\n\n- Drop Exec Shield workaround to fix crashes on recent kernels, where Exec Shield is gone (bsc#1052318).\n","id":"SUSE-SU-2018:0005-1","modified":"2018-01-03T16:37:47Z","published":"2018-01-03T16:37:47Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180005-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049305"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049306"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049307"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049309"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049310"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049311"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049312"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049313"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049314"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049315"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049316"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049318"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049319"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049320"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049321"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049322"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049323"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049324"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049325"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049326"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049327"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049328"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049329"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049330"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049331"},{"type":"REPORT","url":"https://bugzilla.suse.com/1049332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1052318"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064071"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064072"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064073"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064075"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064077"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064078"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064079"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064080"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064081"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064082"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064083"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064084"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064086"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-10165"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9840"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9841"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9842"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-9843"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10067"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10074"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10081"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10086"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10087"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10089"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10096"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10101"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10102"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10105"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10107"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10108"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10109"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10110"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10114"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10115"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10116"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10118"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10125"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10135"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10176"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10193"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10198"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10274"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10281"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10285"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10295"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10345"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10346"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10347"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10348"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10349"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10350"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-10388"}],"related":["CVE-2016-10165","CVE-2016-9840","CVE-2016-9841","CVE-2016-9842","CVE-2016-9843","CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10086","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10105","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10114","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10125","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243","CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"],"summary":"Security update for java-1_7_0-openjdk","upstream":["CVE-2016-10165","CVE-2016-9840","CVE-2016-9841","CVE-2016-9842","CVE-2016-9843","CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10086","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10105","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10114","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10125","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243","CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]}