Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 257349 - dev-java/icedtea6-1.3.1-r1 - multiple vulnerabilities
Summary: dev-java/icedtea6-1.3.1-r1 - multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://icedtea.classpath.org/hg/icedt...
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-02-02 08:17 UTC by Priit Laes (IRC: plaes)
Modified: 2009-04-01 11:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Priit Laes (IRC: plaes) 2009-02-02 08:17:47 UTC
Current IcedTea repository contains fixes for following security issues:

CVE-2008-5360 - Temporary files have guessable file names.
CVE-2008-5350 - Allows to list files within the user home directory.
CVE-2008-5348 - Denial-Of-Service in kerberos authentication.
CVE-2008-5359 - Buffer overflow in image processing.
CVE-2008-5351 - UTF-8 decoder accepts non-shortest form sequences.
CVE-2008-5356 - Font processing vulnerability.
CVE-2008-5353 - Calendar object deserialization allows privilege escalation.
CVE-2008-5354 - Privilege escalation in command line applications.
CVE-2008-5357 - Truetype Font processing vulnerability.
CVE-2008-5352 - Jar200 Decompression buffer overflow.
CVE-2008-5358 - Buffer Overflow in GIF image processing.
Comment 1 Alistair Bush (RETIRED) gentoo-dev 2009-02-02 08:37:53 UTC
No release yet for this.
Comment 2 Andrew John Hughes 2009-02-04 13:07:12 UTC
These security fixes are in the Gentoo 1.3.1 ebuild and have been for sometime.  Please check the ebuild for patches first.

There is also now 1.4 which also has these fixes.
Comment 3 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2009-02-04 13:25:50 UTC
Just to clarify:
dev-java/icedtea6-1.3.1-r2 is fixed, and this package is in java-overlay, not main tree
dev-java/icedtea6-bin-1.3.1-r1 is built from the fixed sources, vulnerable version was never in the main tree. This package is in the main tree, but only ~arch yet.
Which means IIRC no glsa and we are probably done here :) I'll leave it up to the security guys.
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-04-01 11:45:37 UTC
closing without GLSA since it's ~arch only, sorry for the lag.