<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>212425</bug_id>
          <alias>CVE-2008-0628</alias>
          <creation_ts>2008-03-05 20:27 0000</creation_ts>
          <short_desc>dev-java/sun-{jdk,jre-bin}|app-emulation/emul-linux-x86-java} security updates (CVE-2008-{0628,0657,1185,1186,1187,1188,1189,1190,1191,1192,1193,1194,1195,1196})</short_desc>
          <delta_ts>2009-01-11 19:03:01 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>?? [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>165270</blocked>
    
    <blocked>215614</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>java@gentoo.org</cc>
    
    <cc>jussaar@mbnet.fi</cc>
    
    <cc>prote@fmi.uni-stuttgart.de</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2008-03-05 20:27:08 0000</bug_when>
            <thetext>On March 4, 2008, Sun will release the following security updates: 
 
JDK and JRE 6 Update 5
JDK and JRE 5.0 Update 15
SDK and JRE 1.4.2_17
SDK and JRE 1.3.1_22

The following Sun Alerts corresponding to these updates will be released following the availability of these updates. 
 
233321
233322
233323
233324
233325
233326
233327


source: http://blogs.sun.com/security/</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>betelgeuse@gentoo.org</who>
            <bug_when>2008-03-05 20:35:18 0000</bug_when>
            <thetext>Will need to wait for Sun to release DLJ bundles:
https://jdk-distros.dev.java.net/developer.html
22:33 &lt;robogeek&gt; I will check when the DLJ bundles are released, should be shortly</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-03-05 20:46:16 0000</bug_when>
            <thetext>DLJ is not the case of 1.4 which is already available the only usual fetch restricted way.
Adding release just in case, as DJL versions should permit distribution on our media (although I doubt we do that :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-03-05 21:33:49 0000</bug_when>
            <thetext>1.4 added, please stabilize

x86: dev-java/sun-{jdk,jre-bin}-1.4.2.17
amd64: app-emulation/emul-linux-x86-java-1.4.2.17</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-03-06 07:56:40 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jussaar@mbnet.fi</who>
            <bug_when>2008-03-13 00:31:10 0000</bug_when>
            <thetext>*** Bug 213127 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-20 21:07:54 0000</bug_when>
            <thetext>app-emulation/emul-linux-x86-java-1.4.2.17 - amd64 stable.

Fixed in release snapshot.

Vlastimil, we are propagating all security fixes for stable tree to be sure that we are safe.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-26 12:30:36 0000</bug_when>
            <thetext>I heard they&apos;re out now?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-03-26 22:22:41 0000</bug_when>
            <thetext>added, please stabilize

x86+amd64: dev-java/sun-{jdk,jre-bin}-{1.5.0.15,1.6.0.05}
amd64: app-emulation/emul-linux-x86-java-{1.5.0.15,1.6.0.05}
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-03-26 22:23:46 0000</bug_when>
            <thetext>Adding back release to propagate fixes when stabled per comment 6</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-03-26 22:30:15 0000</bug_when>
            <thetext>and my other two friends, amd64 and x86.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-03-27 07:55:19 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-03-27 19:35:36 0000</bug_when>
            <thetext>amd64 stable (last arch)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-03-28 08:16:13 0000</bug_when>
            <thetext>Fixed in release snapshot.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-04-17 23:44:53 0000</bug_when>
            <thetext>GLSA 200804-20, sorry for the long delay.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>