<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>198644</bug_id>
          
          <creation_ts>2007-11-10 11:20 0000</creation_ts>
          <short_desc>dev-java/ibm-jdk-bin &lt;= 1.5.0.5a and &lt;=1.4.2.9 (and ibm-jre-bin) affected by recent Sun JDK security bugs</short_desc>
          <delta_ts>2008-06-26 13:07:07 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www-128.ibm.com/developerworks/java/jdk/alerts/</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>194711</dependson>
          <blocked>215614</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>caster@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>java@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-11-10 11:20:44 0000</bug_when>
            <thetext>From the changelog of ibm-jdk-bin 1.5.0.6:

asdev-20070928	125917	IZ05366	c	N/A	Sun security fixes 6608640 and 6609269
asdev-20070921	125434	IZ04780	c	N/A	Sun Security fix 6605149
asdev-20070915	124940	-	c	N/A	X509Factory does not use SecurityManager
audev-20070914	125019	IZ04776	c	N/A	Sun Security WebRev Bundles Announcement September 08, 2007
asdev-20070914	125019	IZ04776	c	N/A	Sun Security WebRev Bundles Announcement September 08, 2007

You can get the full changelog by going to the download page from here (unfortunately requires registration)
http://www-128.ibm.com/developerworks/java/jdk/linux/download.html
Didn&apos;t find any IBM security advisories, but maybe they exist too.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-11-11 00:02:34 0000</bug_when>
            <thetext>Arches, please stabilize:

dev-java/ibm-jdk-bin-1.5.0.6
dev-java/ibm-jre-bin-1.5.0.6

The distfiles are as usual available via scp from d.g.o/~caster/tmp/
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cla@gentoo.org</who>
            <bug_when>2007-11-11 15:01:47 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-11-12 19:36:14 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>astinus@gentoo.org</who>
            <bug_when>2007-11-14 15:42:39 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-11-18 18:23:37 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2007-11-23 21:43:39 0000</bug_when>
            <thetext>So I found the security alerts url today, and know that 1.4.2.9 is also affected, and the fixed 1.4.2.10 is not yet available so we have to wait.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-02-26 16:35:16 0000</bug_when>
            <thetext>Hm looks like 1.4.2.10 was finally released month ago, so bumped.
Arches, please stabilize:

dev-java/ibm-jdk-bin-1.4.2.10
dev-java/ibm-jre-bin-1.4.2.10

The distfiles will be as usual available via scp from d.g.o/~caster/tmp/

Pretty sure this does not affect release...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-02-26 16:40:44 0000</bug_when>
            <thetext>Adding release just to make sure.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-02-27 09:16:04 0000</bug_when>
            <thetext>IBMJava2-SDK-1.4.2-10.0.tgz is missing, Vlastimil.

/me will never ever touch the IBM interface again.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2008-02-27 09:20:37 0000</bug_when>
            <thetext>Back to ebuild to get this fixed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-02-27 09:35:33 0000</bug_when>
            <thetext>(In reply to comment #10)
&gt; Back to ebuild to get this fixed.

 Not needed, really...masochistic people could get the tarball themselves (and ppc, amd64, ppc64 are complete, by the way).
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2008-02-27 09:37:45 0000</bug_when>
            <thetext>Ahh ok. Thx.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-02-27 21:58:16 0000</bug_when>
            <thetext>Sorry, my upload rate sucks, had to interrupt it and forgot to resume. It&apos;s all there now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-02-28 08:31:45 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-02-29 02:17:08 0000</bug_when>
            <thetext>Pretty sure this is good for ppc64 now, heh, ping if not...stuck in releng work</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-03-05 21:09:20 0000</bug_when>
            <thetext>1.4.2.10 stable for ppc</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2008-03-10 08:58:54 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2008-03-10 16:12:44 0000</bug_when>
            <thetext>And now I&apos;ve done ibm-jre-bin too!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-10 18:09:04 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-05 22:14:26 0000</bug_when>
            <thetext>Yeah, sure, glsa with other ibm bugs :-)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-26 13:07:07 0000</bug_when>
            <thetext>GLSA 200806-11</thetext>
          </long_desc>
      
    </bug>

</bugzilla>