Upstream information

CVE-2016-0475 at MITRE

Description

Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database SUSE
Base Score 5.8 5.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:N AV:N/AC:M/Au:N/C:P/I:P/A:N
Access Vector Network Network
Access Complexity Medium Medium
Authentication None None
Confidentiality Impact Partial Partial
Integrity Impact Partial Partial
Availability Impact None None
SUSE Bugzilla entries: 962743 [RESOLVED / FIXED], 963937 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12 SP1
  • java-1_8_0-openjdk >= 1.8.0.72-3.2
  • java-1_8_0-openjdk-headless >= 1.8.0.72-3.2
Patchnames:
SUSE-SLE-DESKTOP-12-SP1-2016-160
SUSE Linux Enterprise Desktop 12 SP2
  • java-1_8_0-openjdk >= 1.8.0.101-14.3
  • java-1_8_0-openjdk-headless >= 1.8.0.101-14.3
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA java-1_8_0-openjdk
SUSE Linux Enterprise Desktop 12 SP3
  • java-1_8_0-openjdk >= 1.8.0.131-26.3
  • java-1_8_0-openjdk-headless >= 1.8.0.131-26.3
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA java-1_8_0-openjdk
SUSE Linux Enterprise Server 12 SP1
  • java-1_8_0-ibm >= 1.8.0_sr2.10-7.1
  • java-1_8_0-ibm-alsa >= 1.8.0_sr2.10-7.1
  • java-1_8_0-ibm-plugin >= 1.8.0_sr2.10-7.1
  • java-1_8_0-openjdk >= 1.8.0.72-3.2
  • java-1_8_0-openjdk-demo >= 1.8.0.72-3.2
  • java-1_8_0-openjdk-devel >= 1.8.0.72-3.2
  • java-1_8_0-openjdk-headless >= 1.8.0.72-3.2
Patchnames:
SUSE-SLE-SERVER-12-SP1-2016-160
SUSE-SLE-SERVER-12-SP1-2016-227
SUSE Linux Enterprise Server 12 SP2
  • java-1_8_0-ibm >= 1.8.0_sr3.0-10.1
  • java-1_8_0-ibm-alsa >= 1.8.0_sr3.0-10.1
  • java-1_8_0-ibm-plugin >= 1.8.0_sr3.0-10.1
  • java-1_8_0-openjdk >= 1.8.0.101-14.3
  • java-1_8_0-openjdk-demo >= 1.8.0.101-14.3
  • java-1_8_0-openjdk-devel >= 1.8.0.101-14.3
  • java-1_8_0-openjdk-headless >= 1.8.0.101-14.3
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA java-1_8_0-ibm
SUSE Linux Enterprise Server 12 SP2 GA java-1_8_0-openjdk
SUSE Linux Enterprise Server 12 SP3
  • java-1_8_0-ibm >= 1.8.0_sr4.5-29.1
  • java-1_8_0-ibm-alsa >= 1.8.0_sr4.5-29.1
  • java-1_8_0-ibm-plugin >= 1.8.0_sr4.5-29.1
  • java-1_8_0-openjdk >= 1.8.0.131-26.3
  • java-1_8_0-openjdk-demo >= 1.8.0.131-26.3
  • java-1_8_0-openjdk-devel >= 1.8.0.131-26.3
  • java-1_8_0-openjdk-headless >= 1.8.0.131-26.3
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA java-1_8_0-ibm
SUSE Linux Enterprise Server 12 SP3 GA java-1_8_0-openjdk
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • java-1_8_0-openjdk >= 1.8.0.101-14.3
  • java-1_8_0-openjdk-demo >= 1.8.0.101-14.3
  • java-1_8_0-openjdk-devel >= 1.8.0.101-14.3
  • java-1_8_0-openjdk-headless >= 1.8.0.101-14.3
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA java-1_8_0-openjdk
SUSE Linux Enterprise Software Development Kit 12 SP1
  • java-1_8_0-ibm >= 1.8.0_sr2.10-7.1
  • java-1_8_0-ibm-devel >= 1.8.0_sr2.10-7.1
Patchnames:
SUSE-SLE-SDK-12-SP1-2016-227
SUSE Linux Enterprise Software Development Kit 12 SP2
  • java-1_8_0-ibm-devel >= 1.8.0_sr3.0-10.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA java-1_8_0-ibm-devel
SUSE Linux Enterprise Software Development Kit 12 SP3
  • java-1_8_0-ibm-devel >= 1.8.0_sr4.5-29.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP3 GA java-1_8_0-ibm-devel
openSUSE Leap 42.2
  • java-1_8_0-openjdk >= 1.8.0.101-1.1
  • java-1_8_0-openjdk-devel >= 1.8.0.101-1.1
  • java-1_8_0-openjdk-headless >= 1.8.0.101-1.1
Patchnames:
openSUSE Leap 42.2 GA java-1_8_0-openjdk
openSUSE Leap 42.3
  • java-1_8_0-openjdk >= 1.8.0.131-11.1
  • java-1_8_0-openjdk-devel >= 1.8.0.131-11.1
  • java-1_8_0-openjdk-headless >= 1.8.0.131-11.1
Patchnames:
openSUSE Leap 42.3 GA java-1_8_0-openjdk
openSUSE Tumbleweed
  • java-1_8_0-openjdk >= 1.8.0.111-1.1
  • java-1_8_0-openjdk-accessibility >= 1.8.0.111-1.1
  • java-1_8_0-openjdk-demo >= 1.8.0.111-1.1
  • java-1_8_0-openjdk-devel >= 1.8.0.111-1.1
  • java-1_8_0-openjdk-headless >= 1.8.0.111-1.1
  • java-1_8_0-openjdk-javadoc >= 1.8.0.111-1.1
  • java-1_8_0-openjdk-src >= 1.8.0.111-1.1
Patchnames:
openSUSE Tumbleweed GA java-1_8_0-openjdk


Status of this issue by product and package

Product(s) Source package State
SUSE Linux Enterprise Desktop 11 SP3 java-1_7_0-openjdk Released
SUSE Linux Enterprise Desktop 11 SP4 java-1_7_0-openjdk Released
SUSE Linux Enterprise Desktop 12 GA java-1_7_0-openjdk Released
SUSE Linux Enterprise Desktop 12 SP1 java-1_7_0-openjdk Released
SUSE Linux Enterprise Desktop 12 SP1 java-1_8_0-openjdk Released
SUSE Linux Enterprise Server 12 GA java-1_7_0-openjdk Released
SUSE Linux Enterprise Server 12 SP1 java-1_7_0-openjdk Released
SUSE Linux Enterprise Server 12 SP1 java-1_8_0-openjdk Released