Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 205772
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Java team <java@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Stefan Behte <craig@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 205772 depends on: Show dependency tree
Bug 205772 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-01-14 10:32 0000
http://java.sun.com/javase/downloads/index.jsp

Changelog mentions a Buffer Overflow in sun.font.TrueTypeFont.getTableBuffer 
http://java.sun.com/javase/6/webnotes/ReleaseNotes.html#160_04

We should get 1.6.0.04 in the tree ASAP and Mask 1.6.0.03!

------- Comment #1 From Robert Buchholz 2008-01-15 17:59:24 0000 -------
Maybe the site changed in between, but it mentions that a "StackOverflowError"
was caused in that function. Since that happens gracefully within the JVM, how
is that a security vulnerability?

Java herd, did I miss something?

------- Comment #2 From Vlastimil Babka (Caster) 2008-01-15 18:18:53 0000 -------
(In reply to comment #1)
> Maybe the site changed in between, but it mentions that a "StackOverflowError"
> was caused in that function. Since that happens gracefully within the JVM, how
> is that a security vulnerability?

Exactly, it's in the java code, so it's safe. The associated bug also shows a
java exception stack trace, no segfault. Also, I'm sure Sun would release some
advisory.
I expect one anyway, even wanted to open a security bug like "new version was
released, there must be something with the old" when I noticed the release :)
So for now, just a version bump bug, and we are as usually waiting for the
release under DJL license...

------- Comment #3 From Vlastimil Babka (Caster) 2008-01-18 15:06:36 0000 -------
In CVS.

------- Comment #4 From Stefan Behte 2008-01-18 19:48:34 0000 -------
Thanks! :)

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug