Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in java-1_8_0-openjdk
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in java-1_8_0-openjdk
ID: SUSE-SU-2025:1524-1
Distribution: SUSE
Plattformen: SUSE Linux Enterprise Server 12 SP5, SUSE Linux Enterprise High Performance Computing 12 SP5, SUSE Linux Enterprise Server for SAP Applications 12 SP5, SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security, SUSE Linux Enterprise Server 12 SP5 LTSS
Datum: Fr, 9. Mai 2025, 23:40
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30698
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21587
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30691
Applikationen: OpenJDK

Originalnachricht

--===============7755368995793684825==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit



# Security update for java-1_8_0-openjdk

Announcement ID: SUSE-SU-2025:1524-1
Release Date: 2025-05-09T11:29:11Z
Rating: important
References:

* bsc#1241274
* bsc#1241275
* bsc#1241276


Cross-References:

* CVE-2025-21587
* CVE-2025-30691
* CVE-2025-30698


CVSS scores:

* CVE-2025-21587 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-21587 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-21587 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-30691 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2025-30691 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-30691 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-30698 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2025-30698 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2025-30698 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L


Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5
* SUSE Linux Enterprise Server 12 SP5
* SUSE Linux Enterprise Server 12 SP5 LTSS
* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
* SUSE Linux Enterprise Server for SAP Applications 12 SP5



An update that solves three vulnerabilities can now be installed.

## Description:

This update for java-1_8_0-openjdk fixes the following issues:

Update to version jdk8u452 (icedtea-3.35.0)

Security issues fixed:

* CVE-2025-21587: unauthorized creation, deletion or modification of critical
data through the JSSE component. (bsc#1241274)
* CVE-2025-30691: unauthorized update, insert or delete access to a subset of
Oracle Java SE data through the Compiler component. (bsc#1241275)
* CVE-2025-30698: unauthorized access to Oracle Java SE data and unauthorized
ability to cause partial DoS through the 2D component. (bsc#1241276)

Non-security issues fixed:

* JDK-8212096: javax/net/ssl/ServerName/SSLEngineExplorerMatchedSNI.java
failed intermittently due to SSLException: Tag mismatch.
* JDK-8261020: wrong format parameter in create_emergency_chunk_path.
* JDK-8266881: enable debug log for SSLEngineExplorerMatchedSNI.java.
* JDK-8268457: XML Transformer outputs Unicode supplementary character
incorrectly to HTML.
* JDK-8309841: Jarsigner should print a warning if an entry is removed.
* JDK-8337494: clarify JarInputStream behavior.
* JDK-8339637: (tz) update Timezone Data to 2024b.
* JDK-8339644: improve parsing of Day/Month in tzdata rules
* JDK-8339810: clean up the code in sun.tools.jar.Main to properly close
resources and use ZipFile during extract.
* JDK-8340552: harden TzdbZoneRulesCompiler against missing zone names.
* JDK-8342562: enhance Deflater operations.
* JDK-8346587: distrust TLS server certificates anchored by Camerfirma Root
CAs.
* JDK-8347847: enhance jar file support.
* JDK-8347965: (tz) update Timezone Data to 2025a.
* JDK-8348211: [8u] sun/management/jmxremote/startstop/JMXStartStopTest.java
fails after backport of JDK-8066708.
* JDK-8350816: [8u] update TzdbZoneRulesCompiler to ignore HST/EST/MST links.
* JDK-8352097: (tz) zone.tab update missed in 2025a backport.
* JDK-8353433: XCG currency code not recognized in JDK 8u.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 12 SP5 LTSS
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-1524=1

* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
zypper in -t patch
SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1524=1

## Package List:

* SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* java-1_8_0-openjdk-demo-debuginfo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-debuginfo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-demo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-devel-debuginfo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-1.8.0.452-27.114.1
* java-1_8_0-openjdk-headless-1.8.0.452-27.114.1
* java-1_8_0-openjdk-devel-1.8.0.452-27.114.1
* java-1_8_0-openjdk-headless-debuginfo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-debugsource-1.8.0.452-27.114.1
* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64)
* java-1_8_0-openjdk-demo-debuginfo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-debuginfo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-demo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-devel-debuginfo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-1.8.0.452-27.114.1
* java-1_8_0-openjdk-headless-1.8.0.452-27.114.1
* java-1_8_0-openjdk-devel-1.8.0.452-27.114.1
* java-1_8_0-openjdk-headless-debuginfo-1.8.0.452-27.114.1
* java-1_8_0-openjdk-debugsource-1.8.0.452-27.114.1

## References:

* https://www.suse.com/security/cve/CVE-2025-21587.html
* https://www.suse.com/security/cve/CVE-2025-30691.html
* https://www.suse.com/security/cve/CVE-2025-30698.html
* https://bugzilla.suse.com/show_bug.cgi?id=1241274
* https://bugzilla.suse.com/show_bug.cgi?id=1241275
* https://bugzilla.suse.com/show_bug.cgi?id=1241276


--===============7755368995793684825==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit




<div class="container">
<h1>Security update for java-1_8_0-openjdk</h1>

<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2025:1524-1</td>
</tr>
<tr>
<th>Release Date:</th>
<td>2025-05-09T11:29:11Z</td>
</tr>

<tr>
<th>Rating:</th>
<td>important</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1241274">bsc#1241274</a>
</li>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1241275">bsc#1241275</a>
</li>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1241276">bsc#1241276</a>
</li>


</ul>
</td>
</tr>

<tr>
<th>
Cross-References:
</th>
<td>
<ul>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2025-21587.html">CVE-2025-21587</a>
</li>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2025-30691.html">CVE-2025-30691</a>
</li>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2025-30698.html">CVE-2025-30698</a>
</li>

</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-21587</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">9.1</span>
<span
class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-21587</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">7.4</span>
<span
class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-21587</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">7.4</span>
<span
class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-30691</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">6.3</span>
<span
class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-30691</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">4.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-30691</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">4.8</span>
<span
class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-30698</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">6.3</span>
<span
class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-30698</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">5.6</span>
<span
class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2025-30698</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">5.6</span>
<span
class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</span>
</li>

</ul>
</td>
</tr>

<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">

<li class="list-group-item">SUSE Linux
Enterprise High Performance Computing 12 SP5</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 12 SP5</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 12 SP5 LTSS</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 12 SP5 LTSS Extended Security</li>

<li class="list-group-item">SUSE Linux
Enterprise Server for SAP Applications 12 SP5</li>

</ul>
</td>
</tr>
</tbody>
</table>

<p>An update that solves three vulnerabilities can now be
installed.</p>





<h2>Description:</h2>

<p>This update for java-1_8_0-openjdk fixes the following
issues:</p>
<p>Update to version jdk8u452 (icedtea-3.35.0)</p>
<p>Security issues fixed:</p>
<ul>
<li>CVE-2025-21587: unauthorized creation, deletion or modification of
critical data through the JSSE component.
(bsc#1241274)</li>
<li>CVE-2025-30691: unauthorized update, insert or delete access to a
subset of Oracle Java SE data through the Compiler
component. (bsc#1241275)</li>
<li>CVE-2025-30698: unauthorized access to Oracle Java SE data and
unauthorized ability to cause partial DoS through the
2D component. (bsc#1241276)</li>
</ul>
<p>Non-security issues fixed:</p>
<ul>
<li>JDK-8212096:
javax/net/ssl/ServerName/SSLEngineExplorerMatchedSNI.java failed intermittently due to SSLException:
Tag mismatch.</li>
<li>JDK-8261020: wrong format parameter in
create_emergency_chunk_path.</li>
<li>JDK-8266881: enable debug log for
SSLEngineExplorerMatchedSNI.java.</li>
<li>JDK-8268457: XML Transformer outputs Unicode supplementary character
incorrectly to HTML.</li>
<li>JDK-8309841: Jarsigner should print a warning if an entry is
removed.</li>
<li>JDK-8337494: clarify JarInputStream behavior.</li>
<li>JDK-8339637: (tz) update Timezone Data to 2024b.</li>
<li>JDK-8339644: improve parsing of Day/Month in tzdata rules</li>
<li>JDK-8339810: clean up the code in sun.tools.jar.Main to properly
close resources and use ZipFile during extract.</li>
<li>JDK-8340552: harden TzdbZoneRulesCompiler against missing zone
names.</li>
<li>JDK-8342562: enhance Deflater operations.</li>
<li>JDK-8346587: distrust TLS server certificates anchored by Camerfirma
Root CAs.</li>
<li>JDK-8347847: enhance jar file support.</li>
<li>JDK-8347965: (tz) update Timezone Data to 2025a.</li>
<li>JDK-8348211: [8u]
sun/management/jmxremote/startstop/JMXStartStopTest.java fails after backport of JDK-8066708.</li>
<li>JDK-8350816: [8u] update TzdbZoneRulesCompiler to ignore HST/EST/MST
links.</li>
<li>JDK-8352097: (tz) zone.tab update missed in 2025a
backport.</li>
<li>JDK-8353433: XCG currency code not recognized in JDK 8u.</li>
</ul>





<h2>Patch Instructions:</h2>
<p>
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper
patch".<br/>

Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">

<li class="list-group-item">
SUSE Linux Enterprise Server 12 SP5 LTSS


<br/>
<code>zypper in -t patch
SUSE-SLE-SERVER-12-SP5-LTSS-2025-1524=1</code>



</li>

<li class="list-group-item">
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security


<br/>
<code>zypper in -t patch
SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1524=1</code>



</li>

</ul>

<h2>Package List:</h2>
<ul>


<li>
SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le
s390x x86_64)
<ul>


<li>java-1_8_0-openjdk-demo-debuginfo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-debuginfo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-demo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-devel-debuginfo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-headless-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-devel-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-headless-debuginfo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-debugsource-1.8.0.452-27.114.1</li>

</ul>
</li>



<li>
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
(x86_64)
<ul>


<li>java-1_8_0-openjdk-demo-debuginfo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-debuginfo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-demo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-devel-debuginfo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-headless-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-devel-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-headless-debuginfo-1.8.0.452-27.114.1</li>


<li>java-1_8_0-openjdk-debugsource-1.8.0.452-27.114.1</li>

</ul>
</li>


</ul>


<h2>References:</h2>
<ul>


<li>
<a href="https://www.suse.com/security/cve/CVE-2025-21587.html">https://www.suse.com/security/cve/CVE-2025-21587.html</a>
</li>



<li>
<a href="https://www.suse.com/security/cve/CVE-2025-30691.html">https://www.suse.com/security/cve/CVE-2025-30691.html</a>
</li>



<li>
<a href="https://www.suse.com/security/cve/CVE-2025-30698.html">https://www.suse.com/security/cve/CVE-2025-30698.html</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1241274">https://bugzilla.suse.com/show_bug.cgi?id=1241274</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1241275">https://bugzilla.suse.com/show_bug.cgi?id=1241275</a>
</li>



<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1241276">https://bugzilla.suse.com/show_bug.cgi?id=1241276</a>
</li>


</ul>

</div>

--===============7755368995793684825==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung