{"schema_version":"1.7.3","id":"SUSE-SU-2020:0025-1","published":"2020-01-07T12:53:58Z","modified":"2026-02-04T04:39:48.235185Z","related":["CVE-2019-2894","CVE-2019-2933","CVE-2019-2945","CVE-2019-2949","CVE-2019-2958","CVE-2019-2962","CVE-2019-2964","CVE-2019-2973","CVE-2019-2975","CVE-2019-2978","CVE-2019-2981","CVE-2019-2983","CVE-2019-2987","CVE-2019-2988","CVE-2019-2989","CVE-2019-2992","CVE-2019-2999"],"upstream":["CVE-2019-2894","CVE-2019-2933","CVE-2019-2945","CVE-2019-2949","CVE-2019-2958","CVE-2019-2962","CVE-2019-2964","CVE-2019-2973","CVE-2019-2975","CVE-2019-2978","CVE-2019-2981","CVE-2019-2983","CVE-2019-2987","CVE-2019-2988","CVE-2019-2989","CVE-2019-2992","CVE-2019-2999"],"summary":"Security update for java-1_8_0-openjdk","details":"This update for java-1_8_0-openjdk fixes the following issues:\n\nUpdate to version jdk8u232 (icedtea 3.14.0) (October 2019 CPU, bsc#1154212)\n\nSecurity issues fixed:\n\n- CVE-2019-2933: Windows file handling redux\n- CVE-2019-2945: Better socket support\n- CVE-2019-2949: Better Kerberos ccache handling\n- CVE-2019-2958: Build Better Processes\n- CVE-2019-2964: Better support for patterns\n- CVE-2019-2962: Better Glyph Images\n- CVE-2019-2973: Better pattern compilation\n- CVE-2019-2975: Unexpected exception in jjs\n- CVE-2019-2978: Improved handling of jar files\n- CVE-2019-2981: Better Path supports\n- CVE-2019-2983: Better serial attributes\n- CVE-2019-2987: Better rendering of native glyphs\n- CVE-2019-2988: Better Graphics2D drawing\n- CVE-2019-2989: Improve TLS connection support\n- CVE-2019-2992: Enhance font glyph mapping\n- CVE-2019-2999: Commentary on Javadoc comments\n- CVE-2019-2894: Enhance ECDSA operations (bsc#1152856)\n\nBug fixes:\n\n- Add patch to fix hotspot-aarch64 (bsc#1138529).\n","affected":[{"package":{"name":"java-1_8_0-openjdk","ecosystem":"SUSE:Linux Enterprise Desktop 12 SP4","purl":"pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.232-27.38.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openjdk":"1.8.0.232-27.38.1","java-1_8_0-openjdk-headless":"1.8.0.232-27.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:0025-1.json"}},{"package":{"name":"java-1_8_0-openjdk","ecosystem":"SUSE:Linux Enterprise Server 12 SP4","purl":"pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.232-27.38.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openjdk":"1.8.0.232-27.38.1","java-1_8_0-openjdk-demo":"1.8.0.232-27.38.1","java-1_8_0-openjdk-devel":"1.8.0.232-27.38.1","java-1_8_0-openjdk-headless":"1.8.0.232-27.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:0025-1.json"}},{"package":{"name":"java-1_8_0-openjdk","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.232-27.38.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openjdk":"1.8.0.232-27.38.1","java-1_8_0-openjdk-demo":"1.8.0.232-27.38.1","java-1_8_0-openjdk-devel":"1.8.0.232-27.38.1","java-1_8_0-openjdk-headless":"1.8.0.232-27.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:0025-1.json"}},{"package":{"name":"java-1_8_0-openjdk","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.232-27.38.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openjdk":"1.8.0.232-27.38.1","java-1_8_0-openjdk-demo":"1.8.0.232-27.38.1","java-1_8_0-openjdk-devel":"1.8.0.232-27.38.1","java-1_8_0-openjdk-headless":"1.8.0.232-27.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:0025-1.json"}},{"package":{"name":"java-1_8_0-openjdk","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.232-27.38.1"}]}],"ecosystem_specific":{"binaries":[{"java-1_8_0-openjdk":"1.8.0.232-27.38.1","java-1_8_0-openjdk-demo":"1.8.0.232-27.38.1","java-1_8_0-openjdk-devel":"1.8.0.232-27.38.1","java-1_8_0-openjdk-headless":"1.8.0.232-27.38.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:0025-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20200025-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1138529"},{"type":"REPORT","url":"https://bugzilla.suse.com/1152856"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154212"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2894"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2933"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2949"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2964"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2973"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2975"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2989"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2992"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-2999"}]}