Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 567850 - <dev-java/icedtea{,-bin}-7.2.6.3: Vulnerability (CVE-2015-4871)
Summary: <dev-java/icedtea{,-bin}-7.2.6.3: Vulnerability (CVE-2015-4871)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://blog.fuseyism.com/index.php/20...
Whiteboard: B3 [glsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-12-09 13:09 UTC by James Le Cuirot
Modified: 2016-03-12 23:41 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description James Le Cuirot gentoo-dev 2015-12-09 13:09:19 UTC
I'm going to bump icedtea and icedtea-bin now. icedtea doesn't get marked stable so the vulnerable versions will be cleared immediately.
Comment 1 James Le Cuirot gentoo-dev 2015-12-09 13:17:29 UTC
amd64, x86, ppc, and ppc64 arch teams, please stabilise:
dev-java/icedtea-bin-7.2.6.3

ppc64 has never had icedtea-bin:7 before but I wish for this to be stabilised immediately because it's blocking the removal of Java 6, which is next on my list. I haven't yet keyworded plain icedtea for ppc64 because the default HotSpot VM suffers from a race condition, at least on timberdoodle. This icedtea-bin has been built with CACAO instead.
Comment 2 Agostino Sarubbo gentoo-dev 2015-12-09 13:27:39 UTC
(In reply to James Le Cuirot from comment #1)
> ppc64 has never had icedtea-bin:7 before but I wish for this to be
> stabilised immediately because it's blocking the removal of Java 6

Ok but that's not happen here.
Comment 3 James Le Cuirot gentoo-dev 2015-12-09 13:39:47 UTC
(In reply to Agostino Sarubbo from comment #2)
> (In reply to James Le Cuirot from comment #1)
> > ppc64 has never had icedtea-bin:7 before but I wish for this to be
> > stabilised immediately because it's blocking the removal of Java 6
> 
> Ok but that's not happen here.

Actually what I said isn't strictly true, it has had 7 since 22nd Nov but so it is affected by this but it's never been stable before. You want me to file another bug?
Comment 4 Agostino Sarubbo gentoo-dev 2015-12-09 14:49:16 UTC
(In reply to James Le Cuirot from comment #3)
> You want me to file another bug?
Yes
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2015-12-11 04:59:04 UTC
Just to be clear: 
=dev-java/icedtea-bin-7.2.6.3
Target Keywords : "amd64 ppc x86"
Comment 6 James Le Cuirot gentoo-dev 2015-12-11 10:05:48 UTC
(In reply to Yury German from comment #5)
> Just to be clear: 
> =dev-java/icedtea-bin-7.2.6.3
> Target Keywords : "amd64 ppc x86"

Yes.
Comment 7 Agostino Sarubbo gentoo-dev 2015-12-11 10:40:35 UTC
amd64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2015-12-11 10:41:21 UTC
x86 stable
Comment 9 Agostino Sarubbo gentoo-dev 2015-12-26 12:04:35 UTC
ppc stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 10 James Le Cuirot gentoo-dev 2015-12-26 12:15:49 UTC
Thanks, old removed.
Comment 11 Yury German Gentoo Infrastructure gentoo-dev 2015-12-30 21:31:43 UTC
Arches and Maintainer(s), Thank you for your work.

Added to an existing GLSA Request.
Comment 12 GLSAMaker/CVETool Bot gentoo-dev 2016-03-12 23:41:26 UTC
This issue was resolved and addressed in
 GLSA 201603-14 at https://security.gentoo.org/glsa/201603-14
by GLSA coordinator Kristian Fiskerstrand (K_F).