First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 118114
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Petteri Räty <betelgeuse@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 118114 depends on: Show dependency tree
Bug 118114 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-01-06 15:54 0000
http://www.blackdown.org/java-linux/java2-status/security/Blackdown-SA-2005-03.txt
1.4.2.03 is already in the tree so it just needs to be marked stable.

------- Comment #1 From Petteri Räty 2006-01-06 16:22:55 0000 -------
Latest blackdown-jdk and blackdown-jre versions are now stable on x86.

------- Comment #2 From Stefan Cornelius (RETIRED) 2006-01-07 06:28:02 0000 -------
Ok, arches pls try to mark the latest blackdown-jre and -jdk stable. Shouldn't
be a problem for amd64, but maybe there are no fixed packages for ppc and
sparc.

------- Comment #3 From Tobias Scherbaum 2006-01-07 07:47:06 0000 -------
(In reply to comment #2)
> [...] but maybe there are no fixed packages for ppc and sparc.

That's how it look like. The Blackdown SA isn't clear about affected earlier
versions, but from the referenced SUN SA i would guess that our latest stable
versions (blackdown-jdk-1.3.1-r10 and blackdown-jre-1.3.1-r9) are also
affected.

------- Comment #4 From Petteri Räty 2006-01-07 08:13:09 0000 -------
(In reply to comment #2)
> Ok, arches pls try to mark the latest blackdown-jre and -jdk stable. Shouldn't
> be a problem for amd64, but maybe there are no fixed packages for ppc and
> sparc.
> 

sparc being toast has been known for some time. This same issue has come up
with previous 1.4.2 versions.

------- Comment #5 From Joe Jezak 2006-01-07 14:36:33 0000 -------
It would be acceptable to remove the ppc marking from these builds imho, we are
unlikely to see new ppc versions and IBM's JRE/JDK function as a more modern
replacement.

------- Comment #6 From Josh Nichols (RETIRED) 2006-01-07 15:48:58 0000 -------
Marked amd64 stable.

------- Comment #7 From Gustavo Zacarias (RETIRED) 2006-01-09 07:59:43 0000 -------
We're phasing out java altogether for the 2006.0 release, it's all p/u.masked
in the new profile.

------- Comment #8 From Stefan Cornelius (RETIRED) 2006-01-11 23:43:38 0000 -------
i think we issue a tempglsa about this like last time, any other ideas?

------- Comment #9 From Gustavo Zacarias (RETIRED) 2006-01-12 04:55:55 0000 -------
I've placed a nice ad in the 1.4.1 ebuilds about security issues and going away
soon, feel free to adjust too.

------- Comment #10 From Thierry Carrez (RETIRED) 2006-01-12 08:33:03 0000 -------
Yes, temporary GLSA showing (1) ppc and sparc as still affected and (2)
advising users on how to mitigate the vulnerability on those archs (like
switching to IBM for ppc) would be in order.

GLSA editors: see GLSA 200506-14 for inspiration ("Reuse" is your friend here)

------- Comment #11 From Jochen Maes (RETIRED) 2006-01-12 23:25:30 0000 -------
I don't think this is a big issue on ppc. 
Since a year and a half the virtual java ebuild directs to the ibm one. And
frankly the blackdown should be removed as it's unmaintained upstream. 

greetings

------- Comment #12 From Thierry Carrez (RETIRED) 2006-01-13 01:43:00 0000 -------
In fact this also affects Sun's JDK and JRE, see
http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102003-1

Fixed versions include :
    * SDK and JRE 1.3.1_16 and later
    * SDK and JRE 1.4.2_09 and later
    * JDK and JRE 5.0 Update 4 and later

All up-to-date in portage.

------- Comment #13 From Thierry Carrez (RETIRED) 2006-01-16 05:44:44 0000 -------
GLSA 200601-10. It's not really temporary since there probably won't be fixed
versions.

First Last Prev Next    No search results available      Search page      Enter new bug