Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 185256

Summary: {dev-java/{sun-jdk,sun-jre-bin}|app-emulation/emul-linux-x86-java} - multiple vulnerabilities
Product: Gentoo Security Reporter: Carsten Lohrke (RETIRED) <carlo>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: andrei.ivanov, java
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: A2 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 165270, 215614    

Comment 1 Petteri Räty (RETIRED) gentoo-dev 2007-07-14 09:44:47 UTC
(In reply to comment #0)
> http://research.eeye.com/html/advisories/published/AD20070705.html
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102993-1
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102997-1
> 
> 
> Affected are <=1.4.14 <=1.5.11 and <=1.6.1.
> 

Seems only the last one affects all versions and arches but that should be enough. Arches please mark stable:
x86:
dev-java/sun-jdk-1.5.0.12
dev-java/sun-jre-bin-1.5.0.12
dev-java/sun-jre-bin-1.6.0.02
amd64:
dev-java/sun-jdk-1.5.0.12
dev-java/sun-jre-bin-1.5.0.12
dev-java/sun-jre-bin-1.6.0.02
app-emulation/emul-linux-x86-java-1.5.0.12
app-emulation/emul-linux-x86-java-1.6.0.02

We should also bump app-emulation/emul-linux-x86-java to the latest sun-jre-bin version.
Comment 2 Petteri Räty (RETIRED) gentoo-dev 2007-07-14 09:45:08 UTC
forgot arches :)
Comment 3 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2007-07-14 22:23:54 UTC
Renaming because bugzilla search doesn't do bash globbing :)
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2007-07-15 01:49:24 UTC
x86 stable
Comment 5 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2007-07-22 15:44:31 UTC
amd: ping, I see you stabled some java packages today so you're not dead, and this is more important IMHO :)
security: might want to fill the whiteboard?
Comment 6 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-22 18:33:03 UTC
(In reply to comment #5)
> security: might want to fill the whiteboard?
 
indeed :)
Comment 7 Wulf Krueger (RETIRED) gentoo-dev 2007-07-22 19:18:54 UTC
Marked stable on amd64:
dev-java/sun-jdk-1.5.0.12
dev-java/sun-jre-bin-1.5.0.12
dev-java/sun-jre-bin-1.6.0.02
app-emulation/emul-linux-x86-java-1.5.0.12
app-emulation/emul-linux-x86-java-1.6.0.02
Comment 8 Christoph Mende (RETIRED) gentoo-dev 2007-08-01 00:45:21 UTC
is there anything left to do for amd64?
Comment 9 Stefan Behte (RETIRED) gentoo-dev Security 2007-10-14 19:02:10 UTC
GLSA?
Comment 10 Peter Volkov (RETIRED) gentoo-dev 2008-02-25 10:41:28 UTC
This bug does not affect 2008.0, removing release@ from CC.
Comment 11 Robert Buchholz (RETIRED) gentoo-dev 2008-04-17 23:44:36 UTC
GLSA 200804-20, sorry for the long delay.