<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>233652</bug_id>
          
          <creation_ts>2008-08-01 22:23 0000</creation_ts>
          <short_desc>dev-java/ibm-jdk-bin and ibm-jre-bin: multiple vulnerabilities</short_desc>
          <delta_ts>2009-01-14 09:15:27 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>ASSIGNED</bug_status>
          
          <bug_file_loc>http://www.ibm.com/developerworks/java/jdk/alerts/</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>231337</dependson>
          <blocked>215614</blocked>
    
    <blocked>239991</blocked>
    
    <blocked>240384</blocked>
    
    <blocked>252416</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>caster@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>java@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-08-01 22:23:43 0000</bug_when>
            <thetext>As usual, bugs in Sun JDK are likely to affect other vendors also due to shared classes etc, and updatess come after a while after Sun updates. The IBM JDK 1.5.0.8 update I noticed today mentions the following security stuff in changelog (which you probably can&apos;t access without login to IBM site):

asdev-20080626	136205	IZ24898	c	N/A	Sun Security Bulletin 150_16
jsdev-20080613	134284	IZ24844	c	6581221	Sun Security fixes 6450319 6557220 6581221 6607339 6661918
xs2dev-20080613	134284	IZ24844	c	6581221	Sun Security fixes 6450319 6557220 6581221 6607339 6661918

Some of the fix numbers are mentioned in Sun advisories in bug 231337. Not sure if all apply to IBM and are fixed in this version. Seems IBM didn&apos;t release own advisory yet. I&apos;ll at least put the new version in tree and ask for stabling. There are no updates for slots 1.6 and 1.4 yet.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-08-02 12:06:56 0000</bug_when>
            <thetext>Thanks for following this up, please cc arches as yo push updates.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-08-03 21:54:05 0000</bug_when>
            <thetext>Arches please stabilize ibm-jdk-bin and ibm-jre-bin 1.5.0.8. Distfiles as usual via ssh d.g.o/~caster/tmp</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-08-06 19:21:29 0000</bug_when>
            <thetext>amd64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-08-07 18:28:52 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2008-08-19 21:12:47 0000</bug_when>
            <thetext>ppc stable for 1.5.0.8</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-09-09 04:52:50 0000</bug_when>
            <thetext>Bah, instead of the other slots they released 1.5.0.8a which has &quot;Sun Security fix 6332953&quot; which is probably this vuln: http://sunsolve.sun.com/search/document.do?assetkey=1-66-238965-1

So please stabilize ibm-jdk-bin and ibm-jre-bin 1.5.0.8a. Distfiles as usual.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-09-10 13:37:32 0000</bug_when>
            <thetext>ppc and ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ken69267@gentoo.org</who>
            <bug_when>2008-09-10 15:49:26 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-09-12 22:17:12 0000</bug_when>
            <thetext>x86 stable, all arches done for 1.5</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-09-16 07:45:40 0000</bug_when>
            <thetext>So, IBM finally released alerts (in $URL) and a fixed 1.6 which I&apos;m gonna update. No 1.4 yet.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-09-16 09:52:58 0000</bug_when>
            <thetext>ppc/ppc64 please stabilize (other arches don&apos;t have any 1.6 stable yet)

dev-java/ibm-jdk-bin-1.6.0.2

distfiles as usual</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-09-16 09:53:48 0000</bug_when>
            <thetext>(In reply to comment #11)
&gt; ppc/ppc64 please stabilize (other arches don&apos;t have any 1.6 stable yet)
&gt; dev-java/ibm-jdk-bin-1.6.0.2

actually adding arches to CC, sorry...
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-09-17 15:14:07 0000</bug_when>
            <thetext>ppc/ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-10-11 17:16:33 0000</bug_when>
            <thetext>Please stabilize the finally released 1.4.2.12 (jdk and jre), as usual.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-10-11 17:51:31 0000</bug_when>
            <thetext>Turns out in bug 240384 that I&apos;ve used old distfiles for the javacomm optional stuff in 1.6, so ppc/ppc64 please stabilize also ibm-jdk-bin-1.6.0.2-r1 thanks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-10-12 15:12:31 0000</bug_when>
            <thetext>amd64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-10-14 08:17:29 0000</bug_when>
            <thetext>1.6.0.2-r1 stable on ppc/ppc64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-10-14 18:51:32 0000</bug_when>
            <thetext>(In reply to comment #17)
&gt; 1.6.0.2-r1 stable on ppc/ppc64.

Please do also 1.4.2.12 (jdk and jre) see comment 14, sorry for confusion.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-10-15 07:47:38 0000</bug_when>
            <thetext>whoops.. 1.4.2.12 (jdk and jre) stable on ppc/ppc64, too.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2008-10-18 22:04:02 0000</bug_when>
            <thetext>all done except glsa</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-10-19 20:40:35 0000</bug_when>
            <thetext>request filed, thanks caster.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caster@gentoo.org</who>
            <bug_when>2009-01-14 09:15:27 0000</bug_when>
            <thetext>Looks officially obsoleted/additive to bug 252416 now.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>