java-1.8.0-openjdk (SL6, SL7)

Synopsis: Important: java-1.8.0-openjdk security update
Advisory ID: SLSA-2015:1919-1
Issue Date: 2015-10-21
CVE Numbers: CVE-2015-4806
CVE-2015-4835
CVE-2015-4881
CVE-2015-4843
CVE-2015-4883
CVE-2015-4860
CVE-2015-4805
CVE-2015-4844
CVE-2015-4840
CVE-2015-4882
CVE-2015-4842
CVE-2015-4734
CVE-2015-4903
CVE-2015-4803
CVE-2015-4893
CVE-2015-4911
CVE-2015-4872
CVE-2015-4868

Multiple flaws were discovered in the CORBA, Libraries, RMI,
Serialization, and 2D components in OpenJDK. An untrusted Java application
or applet could use these flaws to completely bypass Java sandbox
restrictions. (CVE-2015-4835, CVE-2015-4881, CVE-2015-4843, CVE-2015-4883,
CVE-2015-4860, CVE-2015-4805, CVE-2015-4844)

Multiple denial of service flaws were found in the JAXP component in
OpenJDK. A specially crafted XML file could cause a Java application using
JAXP to consume an excessive amount of CPU and memory when parsed.
(CVE-2015-4803, CVE-2015-4893, CVE-2015-4911)

A flaw was found in the way the Libraries component in OpenJDK handled
certificate revocation lists (CRL). In certain cases, CRL checking code
could fail to report a revoked certificate, causing the application to
accept it as trusted. (CVE-2015-4868)

It was discovered that the Security component in OpenJDK failed to
properly check if a certificate satisfied all defined constraints. In
certain cases, this could cause a Java application to accept an X.509
certificate which does not meet requirements of the defined policy.
(CVE-2015-4872)

Multiple flaws were found in the Libraries, 2D, CORBA, JAXP, JGSS, and RMI
components in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass certain Java sandbox restrictions. (CVE-2015-4806,
CVE-2015-4840, CVE-2015-4882, CVE-2015-4842, CVE-2015-4734, CVE-2015-4903)

All running instances of OpenJDK Java must be restarted for the update to
take effect.

SL6
x86_64
java-1.8.0-openjdk-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-debuginfo-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-headless-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-debug-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-demo-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-demo-debug-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-devel-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-devel-debug-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-headless-debug-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-src-1.8.0.65-0.b17.el6_7.x86_64.rpm
java-1.8.0-openjdk-src-debug-1.8.0.65-0.b17.el6_7.x86_64.rpm
i386
java-1.8.0-openjdk-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-debuginfo-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-headless-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-debug-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-demo-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-demo-debug-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-devel-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-devel-debug-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-headless-debug-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-src-1.8.0.65-0.b17.el6_7.i686.rpm
java-1.8.0-openjdk-src-debug-1.8.0.65-0.b17.el6_7.i686.rpm
noarch
java-1.8.0-openjdk-javadoc-1.8.0.65-0.b17.el6_7.noarch.rpm
java-1.8.0-openjdk-javadoc-debug-1.8.0.65-0.b17.el6_7.noarch.rpm
SL7
x86_64
java-1.8.0-openjdk-1.8.0.65-2.b17.el7_1.x86_64.rpm
java-1.8.0-openjdk-debuginfo-1.8.0.65-2.b17.el7_1.x86_64.rpm
java-1.8.0-openjdk-headless-1.8.0.65-2.b17.el7_1.x86_64.rpm
java-1.8.0-openjdk-accessibility-1.8.0.65-2.b17.el7_1.x86_64.rpm
java-1.8.0-openjdk-demo-1.8.0.65-2.b17.el7_1.x86_64.rpm
java-1.8.0-openjdk-devel-1.8.0.65-2.b17.el7_1.x86_64.rpm
java-1.8.0-openjdk-src-1.8.0.65-2.b17.el7_1.x86_64.rpm
noarch
java-1.8.0-openjdk-javadoc-1.8.0.65-2.b17.el7_1.noarch.rpm

– Scientific Linux Development Team