Errata overview
Errata ID 429
Date 2016-06-01
Source package openjdk-6
Fixed in version 6b38-1.13.10-1.79.201602051147
Description
Multiple vulnerabilities have been discovered in the implementation
of the Java platform. In Univention Corporate Server OpenJDK is
used instead of Oracle Java. This erratum updates OpenJDK to the
release based on JDK 6u111 which fixes these issues:
* Update splashscreen displays (CVE-2015-8126, CVE-2015-8472)
* Better URL processing (CVE-2016-0402)
* Better attributes processing (CVE-2016-0448)
* Reinforce JMX collector internals (S8132210)
* Better printing dialogues (S8132988)
* More general limits (CVE-2016-0466)
* JMX memory management improvements (S8137060)
* Better font substitutions (S8139012)
* More stable image decoding (CVE-2016-0483)
* Arrange font actions (CVE-2016-0494)
* Cleanup for handling proxies (S8143185)
* Expectations should be consistent (CVE-2015-4734)
* Better JAXP data handling (CVE-2015-4803)
* Better handling of remote object invocation (CVE-2015-4903)
* Better CORBA exception handling (CVE-2015-4835)
* Better CORBA value handling (CVE-2015-4882)
* Improve IIOPInputStream consistency (CVE-2015-4881)
* Better JRMP message handling (CVE-2015-4883)
* More supportive home environment (CVE-2015-4842)
* Safer managed types (S8078440)
* More direct property handling (S8080541)
* Service for DGC services (CVE-2015-4860)
* Better group dynamics (S8081760)
* Improve namespace handling (CVE-2015-4893)
* Improve array conversions (S8087350)
* More objective stream classes (CVE-2015-4805)
* Better Binary searches (S8103675)
* Document better processing (CVE-2015-4911)
* Improve HTTP connections (CVE-2015-4806)
* Better server identity handling (S8130864)
* (bf) More direct buffering (CVE-2015-4843)
* Perfect parameter patterning (CVE-2015-4872)
* Preserve layout presentation (CVE-2015-4844)
* Very difficult to exploit vulnerability allows successful
  unauthenticated network attacks via multiple protocols (CVE-2015-7575)
Additional notes
CVE ID CVE-2015-8126
CVE-2015-8472
CVE-2016-0402
CVE-2016-0448
CVE-2016-0466
CVE-2016-0483
CVE-2016-0494
CVE-2015-4734
CVE-2015-4803
CVE-2015-4903
CVE-2015-4835
CVE-2015-4882
CVE-2015-4881
CVE-2015-4883
CVE-2015-4842
CVE-2015-4860
CVE-2015-4893
CVE-2015-4805
CVE-2015-4911
CVE-2015-4806
CVE-2015-4843
CVE-2015-4872
CVE-2015-4844
CVE-2016-0402
CVE-2016-0448
CVE-2016-0466
CVE-2016-0483
CVE-2016-0494
CVE-2015-8126
CVE-2015-8472
CVE-2015-7575
UCS Bug number #40044