SUSE SLES12 安全性更新:java-1_7_1-ibm (SUSE-SU-2015:2168-1) (FREAK)

critical Nessus Plugin ID 87181

概要

遠端 SUSE 主機缺少一個或多個安全性更新。

說明

java-1_7_1-ibm 套件已更新至 7.1-3.20 版以修正數個安全性與非安全性問題:

- bnc#955131:版本更新至 7.1-3.20:CVE-2015-4734 CVE-2015-4803 CVE-2015-4805 CVE-2015-4806 CVE-2015-4810 CVE-2015-4835 CVE-2015-4840 CVE-2015-4842 CVE-2015-4843 CVE-2015-4844 CVE-2015-4860 CVE-2015-4871 CVE-2015-4872 CVE-2015-4882 CVE-2015-4883 CVE-2015-4893 CVE-2015-4902 CVE-2015-4903 CVE-2015-4911 CVE-2015-5006

- 為 sdkdir 新增向後相容符號連結

- bnc#941939:進行修正,以便在 _jvmprivdir 中提供 %{name} 而非只提供 %{sdklnk}

請注意,Tenable Network Security 已直接從 SUSE 安全性公告擷取前置描述區塊。Tenable 已盡量在不造成其他問題的前提下,嘗試自動清理並將其格式化。

解決方案

若要安裝此 SUSE 安全性更新,請使用 YaST online_update。
或者,也可以執行針對您的產品所列的命令:

SUSE Linux Enterprise Software Development Kit 12:

zypper in -t patch SUSE-SLE-SDK-12-2015-920=1

SUSE Linux Enterprise Server 12:

zypper in -t patch SUSE-SLE-SERVER-12-2015-920=1

若要使您的系統保持在最新狀態,請使用「zypper 修補程式」。

另請參閱

https://bugzilla.suse.com/show_bug.cgi?id=941939

https://bugzilla.suse.com/show_bug.cgi?id=955131

https://www.suse.com/security/cve/CVE-2015-0204/

https://www.suse.com/security/cve/CVE-2015-0458/

https://www.suse.com/security/cve/CVE-2015-0459/

https://www.suse.com/security/cve/CVE-2015-0469/

https://www.suse.com/security/cve/CVE-2015-0477/

https://www.suse.com/security/cve/CVE-2015-0478/

https://www.suse.com/security/cve/CVE-2015-0480/

https://www.suse.com/security/cve/CVE-2015-0488/

https://www.suse.com/security/cve/CVE-2015-0491/

https://www.suse.com/security/cve/CVE-2015-4734/

https://www.suse.com/security/cve/CVE-2015-4803/

https://www.suse.com/security/cve/CVE-2015-4805/

https://www.suse.com/security/cve/CVE-2015-4806/

https://www.suse.com/security/cve/CVE-2015-4810/

https://www.suse.com/security/cve/CVE-2015-4835/

https://www.suse.com/security/cve/CVE-2015-4840/

https://www.suse.com/security/cve/CVE-2015-4842/

https://www.suse.com/security/cve/CVE-2015-4843/

https://www.suse.com/security/cve/CVE-2015-4844/

https://www.suse.com/security/cve/CVE-2015-4860/

https://www.suse.com/security/cve/CVE-2015-4871/

https://www.suse.com/security/cve/CVE-2015-4872/

https://www.suse.com/security/cve/CVE-2015-4882/

https://www.suse.com/security/cve/CVE-2015-4883/

https://www.suse.com/security/cve/CVE-2015-4893/

https://www.suse.com/security/cve/CVE-2015-4902/

https://www.suse.com/security/cve/CVE-2015-4903/

https://www.suse.com/security/cve/CVE-2015-4911/

https://www.suse.com/security/cve/CVE-2015-5006/

http://www.nessus.org/u?b7ac6edd

Plugin 詳細資訊

嚴重性: Critical

ID: 87181

檔案名稱: suse_SU-2015-2168-1.nasl

版本: 2.11

類型: local

代理程式: unix

已發布: 2015/12/3

已更新: 2024/6/18

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

風險資訊

VPR

風險因素: Medium

分數: 6.5

CVSS v2

風險因素: Critical

基本分數: 10

時間分數: 8.3

媒介: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2015-4883

弱點資訊

CPE: p-cpe:/a:novell:suse_linux:java-1_7_1-ibm-jdbc, cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:java-1_7_1-ibm-plugin, p-cpe:/a:novell:suse_linux:java-1_7_1-ibm-alsa, p-cpe:/a:novell:suse_linux:java-1_7_1-ibm

必要的 KB 項目: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2015/12/2

弱點發布日期: 2015/1/8

CISA 已知遭惡意利用弱點到期日: 2022/3/24

參考資訊

CVE: CVE-2015-0204, CVE-2015-0458, CVE-2015-0459, CVE-2015-0469, CVE-2015-0477, CVE-2015-0478, CVE-2015-0480, CVE-2015-0488, CVE-2015-0491, CVE-2015-4734, CVE-2015-4803, CVE-2015-4805, CVE-2015-4806, CVE-2015-4810, CVE-2015-4835, CVE-2015-4840, CVE-2015-4842, CVE-2015-4843, CVE-2015-4844, CVE-2015-4860, CVE-2015-4871, CVE-2015-4872, CVE-2015-4882, CVE-2015-4883, CVE-2015-4893, CVE-2015-4902, CVE-2015-4903, CVE-2015-4911, CVE-2015-5006

BID: 71936, 74072, 74083, 74094, 74104, 74111, 74119, 74141, 74147