Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 556022

Summary: <dev-java/oracle-{jdk,jre}-bin-1.8.0.51: Multiple vulnerabilities
Product: Gentoo Security Reporter: Bernd Pachur <gentoo>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: 40cb58f5, java, limanski
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://blogs.oracle.com/security/entry/april_2015_critical_patch_update
Whiteboard:
Package list:
Runtime testing required: ---

Description Bernd Pachur 2015-07-27 11:43:39 UTC
+++ This bug was initially created as a clone of Bug #546678 +++

Oracle JRE/JDK 8u51 was released with fixes of critical security fixes. 
The list of vulnerability reports: http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA

Reproducible: Always
Comment 1 Mike Limansky 2015-07-27 11:50:45 UTC
Looks like a duplicate of bug 554886.
Comment 2 James Le Cuirot gentoo-dev 2015-07-27 11:51:03 UTC
Thanks for the duplicate. Next time, don't search based on the version that fixes the vulnerability. You're supposed to put the version *with* the vulnerability in the title.

*** This bug has been marked as a duplicate of bug 554886 ***
Comment 3 Bernd Pachur 2015-07-27 11:53:22 UTC
Jep! You are right!

Sorry, have not found that when searching!
Comment 4 Mike Limansky 2015-07-27 11:57:04 UTC
(In reply to James Le Cuirot from comment #2)
> Thanks for the duplicate. Next time, don't search based on the version that
> fixes the vulnerability. You're supposed to put the version *with* the
> vulnerability in the title.
> 
> *** This bug has been marked as a duplicate of bug 554886 ***

It's a bit weird. I mean it's a common practice for security team to submit bugs with a *range* of broken versions like >x and <=y or, just <y if all previous versions are affected and the fix is already available. Like here:

https://bugs.gentoo.org/buglist.cgi?component=Vulnerabilities&list_id=2857648&query_format=advanced&resolution=---
Comment 5 James Le Cuirot gentoo-dev 2015-07-27 12:06:21 UTC
(In reply to Mike Limansky from comment #4)
> It's a bit weird. I mean it's a common practice for security team to submit
> bugs with a *range* of broken versions like >x and <=y or, just <y if all
> previous versions are affected and the fix is already available.

Fair enough. I realised after posting that what I said was probably inaccurate and I missed the < on the title of this one. Apologies for my dupe rage.