Summary: | dev-java/ibm-jdk-bin <= 1.5.0.5a and <=1.4.2.9 (and ibm-jre-bin) affected by recent Sun JDK security bugs | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Vlastimil Babka (Caster) (RETIRED) <caster> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | java |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www-128.ibm.com/developerworks/java/jdk/alerts/ | ||
Whiteboard: | B2 [glsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 194711 | ||
Bug Blocks: | 215614 |
Description
Vlastimil Babka (Caster) (RETIRED)
![]() Arches, please stabilize: dev-java/ibm-jdk-bin-1.5.0.6 dev-java/ibm-jre-bin-1.5.0.6 The distfiles are as usual available via scp from d.g.o/~caster/tmp/ x86 stable ppc64 stable stable on amd64 ppc stable So I found the security alerts url today, and know that 1.4.2.9 is also affected, and the fixed 1.4.2.10 is not yet available so we have to wait. Hm looks like 1.4.2.10 was finally released month ago, so bumped. Arches, please stabilize: dev-java/ibm-jdk-bin-1.4.2.10 dev-java/ibm-jre-bin-1.4.2.10 The distfiles will be as usual available via scp from d.g.o/~caster/tmp/ Pretty sure this does not affect release... Adding release just to make sure. IBMJava2-SDK-1.4.2-10.0.tgz is missing, Vlastimil. /me will never ever touch the IBM interface again. Back to ebuild to get this fixed. (In reply to comment #10) > Back to ebuild to get this fixed. Not needed, really...masochistic people could get the tarball themselves (and ppc, amd64, ppc64 are complete, by the way). Ahh ok. Thx. Sorry, my upload rate sucks, had to interrupt it and forgot to resume. It's all there now. x86 stable Pretty sure this is good for ppc64 now, heh, ping if not...stuck in releng work 1.4.2.10 stable for ppc amd64 stable And now I've done ibm-jre-bin too! Fixed in release snapshot. Yeah, sure, glsa with other ibm bugs :-) GLSA 200806-11 |