Bugzilla – Bug 972468
VUL-0: CVE-2016-0636: java-1_7_0-openjdk, java-1_8_0-openjdk: out-of-band urgent security fix (Hotspot, 8151666)
Last modified: 2017-05-11 00:55:48 UTC
rh#1320650 Public now via "Oracle Security Alert for CVE-2016-0636": http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0636-2949497.html https://blogs.oracle.com/security/entry/security_alert_cve_2016_0636 fixed versions are 7u99 and 8u77. References: http://www.oracle.com/technetwork/java/javase/8u77-relnotes-2944725.html http://seclists.org/fulldisclosure/2016/Mar/31 https://bugzilla.redhat.com/show_bug.cgi?id=1320650 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0636
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (972468) was mentioned in https://build.opensuse.org/request/show/380700 Factory / java-1_7_0-openjdk
This is an autogenerated message for OBS integration: This bug (972468) was mentioned in https://build.opensuse.org/request/show/380907 13.1 / java-1_7_0-openjdk https://build.opensuse.org/request/show/380925 13.2 / java-1_7_0-openjdk
This is an autogenerated message for OBS integration: This bug (972468) was mentioned in https://build.opensuse.org/request/show/381447 Factory / java-1_8_0-openjdk https://build.opensuse.org/request/show/381450 13.2 / java-1_8_0-openjdk
QA saw that libcups.so.2 was no longer required. I think CUPS support is broken by this update. reason: SYSTEM_CUPS changed from true -> yes if enabled. but lots of makefiles or almost all places still use ifneq ($(SYSTEM_CUPS), true) ifeq ($(SYSTEM_CUPS), true) Can you report this upstream?
https://docs.oracle.com/javase/tutorial/2d/printing/examples/HelloWorldPrinter.java javac HelloWorldPrinter.java java HelloWorldPrinter will open a window with a button ... Press this button.
(it still seems able to print, and loads libcups.so.2 dynamically apparently.) so it seems not buggy
SUSE-SU-2016:0956-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 972468 CVE References: CVE-2016-0636 Sources used: SUSE Linux Enterprise Desktop 11-SP4 (src): java-1_7_0-openjdk-1.7.0.99-0.20.2 SUSE Linux Enterprise Debuginfo 11-SP4 (src): java-1_7_0-openjdk-1.7.0.99-0.20.2
SUSE-SU-2016:0957-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 972468 CVE References: CVE-2016-0636 Sources used: SUSE Linux Enterprise Server 12-SP1 (src): java-1_8_0-openjdk-1.8.0.77-6.1 SUSE Linux Enterprise Desktop 12-SP1 (src): java-1_8_0-openjdk-1.8.0.77-6.1
SUSE-SU-2016:0959-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 972468 CVE References: CVE-2016-0636 Sources used: SUSE Linux Enterprise Server 12-SP1 (src): java-1_7_0-openjdk-1.7.0.99-27.1 SUSE Linux Enterprise Server 12 (src): java-1_7_0-openjdk-1.7.0.99-27.1 SUSE Linux Enterprise Desktop 12-SP1 (src): java-1_7_0-openjdk-1.7.0.99-27.1 SUSE Linux Enterprise Desktop 12 (src): java-1_7_0-openjdk-1.7.0.99-27.1
openSUSE-SU-2016:0971-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 972468 CVE References: CVE-2016-0636 Sources used: openSUSE 13.2 (src): java-1_7_0-openjdk-1.7.0.99-19.1, java-1_7_0-openjdk-bootstrap-1.7.0.99-19.1
openSUSE-SU-2016:0983-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 972468 CVE References: CVE-2016-0636 Sources used: openSUSE 13.2 (src): java-1_8_0-openjdk-1.8.0.77-24.1
Is there an update for leap available?
openSUSE-SU-2016:1004-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 972468 CVE References: CVE-2016-0636 Sources used: openSUSE Leap 42.1 (src): java-1_7_0-openjdk-1.7.0.99-28.1, java-1_7_0-openjdk-bootstrap-1.7.0.99-28.1
openSUSE-SU-2016:1005-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 972468 CVE References: CVE-2016-0636 Sources used: openSUSE Leap 42.1 (src): java-1_8_0-openjdk-1.8.0.77-9.1
released yesterday :)
(In reply to Marcus Meissner from comment #19) > released yesterday :) Thank you. I'd suggest a button for from SLE-inheritet patches :-)
openSUSE-SU-2016:1042-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 972468 CVE References: CVE-2016-0636 Sources used: openSUSE 13.1 (src): java-1_7_0-openjdk-1.7.0.99-24.33.2