{"id":"SUSE-SU-2018:0645-1","summary":"Security update for java-1_7_0-ibm","details":"\n  \nThis update for java-1_7_0-ibm provides the following fixes:\n\nThe version was updated to 7.0.10.20 [bsc#1082810]:\n\n* Following security issues were fixed:\n\n  - CVE-2018-2633 CVE-2018-2637 CVE-2018-2634 CVE-2018-2582\n    CVE-2018-2641 CVE-2018-2618 CVE-2018-2657 CVE-2018-2603\n    CVE-2018-2599 CVE-2018-2602 CVE-2018-2678 CVE-2018-2677\n    CVE-2018-2663 CVE-2018-2588 CVE-2018-2579\n\n* Defect fixes:\n\n    - IJ04281 Class Libraries: Startup time increase after applying\n      \t      apar IV96905\n    - IJ03822 Class Libraries: Update timezone information to tzdata2017c\n    - IJ03605 Java Virtual Machine: Legacy security for com.ibm.jvm.dump,\n      \t      trace, log was not enabled by default\n    - IJ03607 JIT Compiler: Result String contains a redundant dot when\n      \t      converted from BigDecimal with 0 on all platforms\n    - IX90185 ORB: Upgrade ibmcfw.jar to version O1800.01\n    - IJ04282 Security: Change in location and default of jurisdiction\n      \t      policy files\n    - IJ03853 Security: IBMCAC provider does not support SHA224\n    - IJ02679 Security: IBMPKCS11Impl – Bad sessions are being allocated\n      \t      internally\n    - IJ02706 Security: IBMPKCS11Impl – Bad sessions are being allocated\n      \t      internally\n    - IJ03552 Security: IBMPKCS11Impl - Config file problem with the slot\n      \t      specification attribute\n    - IJ01901 Security: IBMPKCS11Impl – SecureRandom.setSeed() exception\n    - IJ03801 Security: Issue with same DN certs, iKeyman GUI error with\n      \t      stash, JKS Chain issue and JVM argument parse issue with iKeyman\n    - IJ02284 JIT Compiler: Division by zero in JIT compiler\n\n    - Make it possible to run Java jnlp files from Firefox. (bsc#1057460)\n\n","modified":"2025-05-02T04:08:12.398005Z","published":"2018-03-09T07:25:29Z","related":["CVE-2018-2579","CVE-2018-2582","CVE-2018-2588","CVE-2018-2599","CVE-2018-2602","CVE-2018-2603","CVE-2018-2618","CVE-2018-2633","CVE-2018-2634","CVE-2018-2637","CVE-2018-2641","CVE-2018-2657","CVE-2018-2663","CVE-2018-2677","CVE-2018-2678"],"upstream":["CVE-2018-2579","CVE-2018-2582","CVE-2018-2588","CVE-2018-2599","CVE-2018-2602","CVE-2018-2603","CVE-2018-2618","CVE-2018-2633","CVE-2018-2634","CVE-2018-2637","CVE-2018-2641","CVE-2018-2657","CVE-2018-2663","CVE-2018-2677","CVE-2018-2678"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180645-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1057460"},{"type":"REPORT","url":"https://bugzilla.suse.com/1076390"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082810"},{"type":"REPORT","url":"https://bugzilla.suse.com/929900"},{"type":"REPORT","url":"https://bugzilla.suse.com/966304"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2579"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2582"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2599"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2602"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2603"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2633"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2634"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2641"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2657"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2663"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-2678"}],"affected":[{"package":{"name":"java-1_7_0-ibm","ecosystem":"SUSE:Linux Enterprise Point of Sale 11 SP3","purl":"pkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0_sr10.20-65.13.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_7_0-ibm":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-alsa":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-devel":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-jdbc":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-plugin":"1.7.0_sr10.20-65.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0645-1.json"}},{"package":{"name":"java-1_7_0-ibm","ecosystem":"SUSE:Linux Enterprise Server 11 SP3-LTSS","purl":"pkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0_sr10.20-65.13.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_7_0-ibm-alsa":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-devel":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-jdbc":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-plugin":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm":"1.7.0_sr10.20-65.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0645-1.json"}},{"package":{"name":"java-1_7_0-ibm","ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","purl":"pkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0_sr10.20-65.13.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_7_0-ibm-alsa":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-devel":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-jdbc":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm-plugin":"1.7.0_sr10.20-65.13.1","java-1_7_0-ibm":"1.7.0_sr10.20-65.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0645-1.json"}}],"schema_version":"1.7.3"}