{"affected":[{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP1","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-demo":"1.7.0.131-39.1","java-1_7_0-openjdk-devel":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-demo":"1.7.0.131-39.1","java-1_7_0-openjdk-devel":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-demo":"1.7.0.131-39.1","java-1_7_0-openjdk-devel":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-demo":"1.7.0.131-39.1","java-1_7_0-openjdk-devel":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP1","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-demo":"1.7.0.131-39.1","java-1_7_0-openjdk-devel":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP1","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-demo":"1.7.0.131-39.1","java-1_7_0-openjdk-devel":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"java-1_7_0-openjdk":"1.7.0.131-39.1","java-1_7_0-openjdk-demo":"1.7.0.131-39.1","java-1_7_0-openjdk-devel":"1.7.0.131-39.1","java-1_7_0-openjdk-headless":"1.7.0.131-39.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"java-1_7_0-openjdk","purl":"pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.7.0.131-39.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis update for java-1_7_0-openjdk fixes the following issues:\n\n- Oracle Critical Patch Update of January 2017 to OpenJDK 7u131 (bsc#1020905):\n  * Security Fixes\n    - S8138725: Add options for Javadoc generation\n    - S8140353: Improve signature checking\n    - S8151934, CVE-2017-3231: Resolve class resolution\n    - S8156804, CVE-2017-3241: Better constraint checking\n    - S8158406: Limited Parameter Processing\n    - S8158997: JNDI Protocols Switch\n    - S8159507: RuntimeVisibleAnnotation validation\n    - S8161218: Better bytecode loading\n    - S8161743, CVE-2017-3252: Provide proper login context\n    - S8162577: Standardize logging levels\n    - S8162973: Better component components\n    - S8164143, CVE-2017-3260: Improve components for menu items\n    - S8164147, CVE-2017-3261: Improve streaming socket output\n    - S8165071, CVE-2016-2183: Expand TLS support\n    - S8165344, CVE-2017-3272: Update concurrency support\n    - S8166988, CVE-2017-3253: Improve image processing performance\n    - S8167104, CVE-2017-3289: Additional class construction refinements\n    - S8167223, CVE-2016-5552: URL handling improvements\n    - S8168705, CVE-2016-5547: Better ObjectIdentifier validation\n    - S8168714, CVE-2016-5546: Tighten ECDSA validation\n    - S8168728, CVE-2016-5548: DSA signing improvments\n    - S8168724, CVE-2016-5549: ECDSA signing improvments\n    - S6253144: Long narrowing conversion should describe the algorithm used and implied 'risks'\n    - S6328537: Improve javadocs for Socket class by adding references to SocketOptions\n    - S6978886: javadoc shows stacktrace after print error resulting from disk full\n    - S6995421: Eliminate the static dependency to sun.security.ec.ECKeyFactory\n    - S6996372: synchronizing handshaking hash\n    - S7027045: (doc) java/awt/Window.java has several typos in javadoc\n    - S7054969: Null-check-in-finally pattern in java/security documentation\n    - S7072353: JNDI libraries do not build with javac -Xlint:all -Werror\n    - S7075563: Broken link in 'javax.swing.SwingWorker'\n    - S7077672: jdk8_tl nightly fail in step-2 build on 8/10/11\n    - S7088502: Security libraries don't build with javac -Werror\n    - S7092447: Clarify the default locale used in each locale sensitive operation\n    - S7093640: Enable client-side TLS 1.2 by default\n    - S7103570: AtomicIntegerFieldUpdater does not work when SecurityManager is installed\n    - S7117360: Warnings in java.util.concurrent.atomic package\n    - S7117465: Warning cleanup for IMF classes\n    - S7187144: JavaDoc for ScriptEngineFactory.getProgram() contains an error\n    - S8000418: javadoc should used a standard 'generated by javadoc' string\n    - S8000666: javadoc should write directly to Writer instead of composing strings\n    - S8000673: remove dead code from HtmlWriter and subtypes\n    - S8000970: break out auxiliary classes that will prevent multi-core compilation of the JDK\n    - S8001669: javadoc internal DocletAbortException should set cause when appropriate\n    - S8008949: javadoc stopped copying doc-files\n    - S8011402: Move blacklisting certificate logic from hard code to data\n    - S8011547: Update XML Signature implementation to Apache Santuario 1.5.4\n    - S8012288: XML DSig API allows wrong tag names and extra elements in SignedInfo\n    - S8016217: More javadoc warnings\n    - S8017325: Cleanup of the javadoc <code> tag in java.security.cert\n    - S8017326: Cleanup of the javadoc <code> tag in java.security.spec\n    - S8019772: Fix doclint issues in javax.crypto and javax.security subpackages\n    - S8020557: javadoc cleanup in javax.security\n    - S8020688: Broken links in documentation at http://docs.oracle.com/javase/6/docs/api/index.\n    - S8021108: Clean up doclint warnings and errors in java.text package\n    - S8021417: Fix doclint issues in java.util.concurrent\n    - S8021833: javadoc cleanup in java.net\n    - S8022120: JCK test api/javax_xml/crypto/dsig/TransformService/index_ParamMethods fails\n    - S8022175: Fix doclint warnings in javax.print\n    - S8022406: Fix doclint issues in java.beans\n    - S8022746: List of spelling errors in API doc\n    - S8024779: [macosx] SwingNode crashes on exit\n    - S8025085: [javadoc] some errors in javax/swing\n    - S8025218: [javadoc] some errors in java/awt classes\n    - S8025249: [javadoc] fix some javadoc errors in javax/swing/\n    - S8025409: Fix javadoc comments errors and warning reported by doclint report\n    - S8026021: more fix of javadoc errors and warnings reported by doclint, see the description\n    - S8037099: [macosx] Remove all references to GC from native OBJ-C code\n    - S8038184: XMLSignature throws StringIndexOutOfBoundsException if ID attribute value is empty String\n    - S8038349: Signing XML with DSA throws Exception when key is larger than 1024 bits\n    - S8049244: XML Signature performance issue caused by unbuffered signature data\n    - S8049432: New tests for TLS property jdk.tls.client.protocols\n    - S8050893: (smartcardio) Invert reset argument in tests in sun/security/smartcardio\n    - S8059212: Modify regression tests so that they do not just fail if no cardreader found\n    - S8068279: (typo in the spec) javax.script.ScriptEngineFactory.getLanguageName\n    - S8068491: Update the protocol for references of docs.oracle.com to HTTPS.\n    - S8069038: javax/net/ssl/TLS/TLSClientPropertyTest.java needs to be updated for JDK-8061210\n    - S8076369: Introduce the jdk.tls.client.protocols system property for JDK 7u\n    - S8139565: Restrict certificates with DSA keys less than 1024 bits\n    - S8140422: Add mechanism to allow non default root CAs to be not subject to algorithm restrictions\n    - S8140587: Atomic*FieldUpdaters should use Class.isInstance instead of direct class check\n    - S8143959: Certificates requiring blacklisting\n    - S8145984: [macosx] sun.lwawt.macosx.CAccessible leaks\n    - S8148516: Improve the default strength of EC in JDK\n    - S8149029: Secure validation of XML based digital signature always enabled when checking wrapping attacks\n    - S8151893: Add security property to configure XML Signature secure validation mode\n    - S8155760: Implement Serialization Filtering\n    - S8156802: Better constraint checking\n    - S8161228: URL objects with custom protocol handlers have port changed after deserializing\n    - S8161571: Verifying ECDSA signatures permits trailing bytes\n    - S8163304: jarsigner -verbose -verify should print the algorithms used to sign the jar\n    - S8164908: ReflectionFactory support for IIOP and custom serialization\n    - S8165230: RMIConnection addNotificationListeners failing with specific inputs\n    - S8166393: disabledAlgorithms property should not be strictly parsed\n    - S8166591: [macos 10.12] Trackpad scrolling of text on OS X 10.12 Sierra is very fast (Trackpad, Retina only)\n    - S8166739: Improve extensibility of ObjectInputFilter information passed to the filter\n    - S8166875: (tz) Support tzdata2016g\n    - S8166878: Connection reset during TLS handshake\n    - S8167356: Follow up fix for jdk8 backport of 8164143. Changes for CMenuComponent.m were missed\n    - S8167459: Add debug output for indicating if a chosen ciphersuite was legacy\n    - S8167472: Chrome interop regression with JDK-8148516\n    - S8167591: Add MD5 to signed JAR restrictions\n    - S8168861: AnchorCertificates uses hardcoded password for cacerts keystore\n    - S8168993: JDK8u121 L10n resource file update\n    - S8169191: (tz) Support tzdata2016i\n    - S8169688: Backout (remove) MD5 from jdk.jar.disabledAlgorithms for January CPU\n    - S8169911: Enhanced tests for jarsigner -verbose -verify after JDK-8163304\n    - S8170131: Certificates not being blocked by jdk.tls.disabledAlgorithms property\n    - S8170268: 8u121 L10n resource file update - msgdrop 20\n    - S8173622: Backport of 7180907 is incomplete\n    - S8173849: Fix use of java.util.Base64 in test cases\n    - S8173854: [TEST] Update DHEKeySizing test case following 8076328 & 8081760\n    - CVE-2017-3259 Vulnerability allows unauthenticated attacker with network access via multiple protocols to\n      compromise Java SE.\n  * Backports\n    - S7102489, PR3316, RH1390708: RFE: cleanup jlong typedef on __APPLE__and _LLP64 systems.\n    - S8000351, PR3316, RH1390708: Tenuring threshold should be unsigned\n    - S8153711, PR3315, RH1284948: [REDO] GlobalRefs never deleted when processing invokeMethod command\n    - S8170888, PR3316, RH1390708: [linux] support for cgroup memory limits in container (ie Docker) environments\n  * Bug fixes\n    - PR3318: Replace 'infinality' with 'improved font rendering' (--enable-improved-font-rendering)\n    - PR3318: Fix compatibility with vanilla Fontconfig\n    - PR3318: Fix glyph y advance\n    - PR3318: Always round glyph advance in 26.6 space\n    - PR3318: Simplify glyph advance handling\n    - PR3324: Fix NSS_LIBDIR substitution in make_generic_profile.sh broken by PR1989\n  * AArch64 port\n    - S8165673, PR3320: AArch64: Fix JNI floating point argument handling\n","id":"SUSE-SU-2017:0490-1","modified":"2017-02-17T09:59:41Z","published":"2017-02-17T09:59:41Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20170490-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1020905"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-2183"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5547"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5548"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5549"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-5552"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3231"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3241"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3252"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3253"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3259"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3260"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3261"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3272"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-3289"}],"related":["CVE-2016-2183","CVE-2016-5546","CVE-2016-5547","CVE-2016-5548","CVE-2016-5549","CVE-2016-5552","CVE-2017-3231","CVE-2017-3241","CVE-2017-3252","CVE-2017-3253","CVE-2017-3259","CVE-2017-3260","CVE-2017-3261","CVE-2017-3272","CVE-2017-3289"],"summary":"Security update for java-1_7_0-openjdk","upstream":["CVE-2016-2183","CVE-2016-5546","CVE-2016-5547","CVE-2016-5548","CVE-2016-5549","CVE-2016-5552","CVE-2017-3231","CVE-2017-3241","CVE-2017-3252","CVE-2017-3253","CVE-2017-3259","CVE-2017-3260","CVE-2017-3261","CVE-2017-3272","CVE-2017-3289"]}