This update for java-180-openjdk to the jdk8u181 (icedtea 3.9.0) release fixes the following issues:
These security issues were fixed:
CVE-2018-2938: Difficult to exploit vulnerability allowed unauthenticated
attacker with network access via multiple protocols to compromise Java SE.
Successful attacks of this vulnerability can result in takeover of Java SE
(bsc#1101644).
CVE-2018-2940: Vulnerability in subcomponent: Libraries. Easily exploitable
vulnerability allowed unauthenticated attacker with network access via multiple
protocols to compromise Java SE, Java SE Embedded. Successful attacks require
human interaction from a person other than the attacker. Successful attacks of
this vulnerability can result in unauthorized read access to a subset of Java
SE, Java SE Embedded accessible data (bsc#1101645)
CVE-2018-2952: Vulnerability in subcomponent: Concurrency. Difficult to
exploit vulnerability allowed unauthenticated attacker with network access via
multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful
attacks of this vulnerability can result in unauthorized ability to cause a
partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit
(bsc#1101651)
CVE-2018-2973: Vulnerability in subcomponent: JSSE. Difficult to exploit
vulnerability allowed unauthenticated attacker with network access via SSL/TLS
to compromise Java SE, Java SE Embedded. Successful attacks of this
vulnerability can result in unauthorized creation, deletion or modification
access to critical data or all Java SE, Java SE Embedded accessible data
(bsc#1101656)
These non-security issues were fixed:
Improve desktop file usage
Better Internet address support
speculative traps break when classes are redefined