<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>194711</bug_id>
          
          <creation_ts>2007-10-04 14:07 0000</creation_ts>
          <short_desc>security bugs in &lt;=dev-java/sun-j[dk,re]-1.6.0.02 / &lt;=dev-java/sun-j[dk,re]-1.5.0.12 / &lt;=dev-java/sun-j[dk,re]-1.4.2.15 (CVE-2007-{5232,5237,5238,5239,5240,5273,5274,5689})</short_desc>
          <delta_ts>2008-04-17 23:44:43 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>? [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>178962</dependson>
          <blocked>198644</blocked>
    
    <blocked>215614</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>craig@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bernd@linx.net</cc>
    
    <cc>chainsaw@gentoo.org</cc>
    
    <cc>java@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>craig@gentoo.org</who>
            <bug_when>2007-10-04 14:07:09 0000</bug_when>
            <thetext>Hi, the bug reports can be found at:

http://sunsolve.sun.com/search/document.do?assetkey=1-26-103079-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103071-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103073-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103072-1

Affected Versions:
    * JDK and JRE 6 Update 2 and earlier
    * JDK and JRE 5.0 Update 12 and earlier
    * SDK and JRE 1.4.2_15 and earlier
    * SDK and JRE 1.3.1_20 and earlier

JDK:
dev-java/sun-jdk-1.5.0.13 is in portage, but it&apos;s keyworded, we should stabilize it ASAP and mask 1.5.0.12. The same applies to 1.6.0.02/1.6.0.03.

1.4.2.16 is not in portage yet, should be added and then 1.4.2.15 should be masked, too.

JRE:
For dev-java/sun-jre there are only vulnerable versions in portage. We need the new ones and then the old ones should be masked.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>betelgeuse@gentoo.org</who>
            <bug_when>2007-10-04 14:27:06 0000</bug_when>
            <thetext>amd64:
sun-jdk-1.5.0.13
sun-jdk-1.6.0.03
sun-jre-bin-1.5.0.13
sun-jre-bin-1.6.0.03
emul-linux-x86-java-1.5.0.13
emul-linux-x86-java-1.6.0.03
x86:
sun-jdk-1.4.2.16
sun-jdk-1.5.0.13
sun-jdk-1.6.0.03
sun-jre-bin-1.4.2.16
sun-jre-bin-1.5.0.13
sun-jre-bin-1.6.0.03</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-10-04 18:47:03 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-10-04 23:11:42 0000</bug_when>
            <thetext>Don&apos;t miss app-emulation/emul-linux-x86-java in the GLSA. Also the three month old bug 185256 didn&apos;t got a GLSA yet...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-10-12 00:35:05 0000</bug_when>
            <thetext>amd64 stable, along with java-sdk-docs and sun-jce-bin 1.6.0 deps</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>chithanh@cs.tu-berlin.de</who>
            <bug_when>2007-10-19 14:42:59 0000</bug_when>
            <thetext>(In reply to comment #4)
&gt; amd64 stable, along with java-sdk-docs and sun-jce-bin 1.6.0 deps

maybe you could also mark virtual/jdk-1.6.0 stable while you are at it?
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wltjr@gentoo.org</who>
            <bug_when>2007-10-19 14:56:54 0000</bug_when>
            <thetext>virtual/jdk-1.6.0 stable on amd64, thanks for mentioning repoman didn&apos;t catch it, and I forgot about it :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-24 01:12:11 0000</bug_when>
            <thetext>New vulnerability that should be mentioned in a GLSA.

A vulnerability in the Virtual Machine of the Java Runtime Environment may allow an untrusted applet to elevate its privileges. For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.

..
This issue is addressed in the following releases (for Windows, Solaris, and Linux):

    * JDK and JRE 6 Update 3 or later
    * JDK and JRE 5.0 Update 13 or later
    * SDK and JRE 1.4.2_16 or later

http://sunsolve.sun.com/search/document.do?assetkey=1-26-103112-1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2007-10-24 01:12:33 0000</bug_when>
            <thetext>amd64, is there anything left to do for you?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-11-03 15:59:37 0000</bug_when>
            <thetext>amd64 was done long ago.
Just the emul-linux-x86-java-1.4 stabling in bug 178962 and a GLSA on this could superseed and finally close all those open bugs on sun and emul stuff pending just glsa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2007-11-06 23:44:12 0000</bug_when>
            <thetext>OK.  I now have everything done for amd64...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-02-25 10:42:44 0000</bug_when>
            <thetext>This bug does not affect 2008.0 snapshot, removing release@ from CC.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-01 16:55:16 0000</bug_when>
            <thetext>http://sunsolve.sun.com/search/document.do?assetkey=1-26-103112-1</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-17 23:44:43 0000</bug_when>
            <thetext>GLSA 200804-20, sorry for the long delay.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>