Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 216112

Summary: dev-java/ibm-jdk-bin < 1.6.0.1 and < 1.5.0.7 and <1.4.2.11 (and ibm-jre-bin) Multiple vulnerabilities
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: betelgeuse, java, releng
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B2 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on:    
Bug Blocks: 215614    

Description Robert Buchholz (RETIRED) gentoo-dev 2008-04-03 23:50:26 UTC
The following IBM Java releases just came out, fixing the Sun stuff from bug 212425.
6 SR1 and later
5.0 SR7 and later
1.4.2 SR11 and later
Comment 1 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2008-04-04 08:44:48 UTC
http://www.ibm.com/developerworks/java/jdk/linux/download.html

I can see only 5.0 SR7 released yet. Delays between the slots are unfortunately nothing new for IBM, like releasing fixed version more than month after the advisory...
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-04-04 09:21:54 UTC
True, I only checked 1.5. It took me until now to understand that the terms "GA" or "SR7" for the download links are actually version specifiers.
Comment 3 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2008-04-04 15:24:45 UTC
Okay, first round of stabilization!
dev-java/ibm-jdk-bin-1.5.0.7
dev-java/ibm-jre-bin-1.5.0.7

distfiles as usual (ssh d.g.o:~caster/tmp)
you'll have to use repoman commit --force due to bug 216198
Comment 4 Markus Meier gentoo-dev 2008-04-06 13:57:04 UTC
amd64/x86 stable
Comment 5 Markus Rothe (RETIRED) gentoo-dev 2008-04-06 20:11:58 UTC
ppc64 stable
Comment 6 Tobias Scherbaum (RETIRED) gentoo-dev 2008-04-06 20:33:25 UTC
ppc stable, re-adding x86/amd64 for dev-java/ibm-jre-bin.
Comment 7 Markus Meier gentoo-dev 2008-04-07 20:55:15 UTC
forgot to commit that one, amd64/x86 stable.
Comment 8 Peter Volkov (RETIRED) gentoo-dev 2008-04-08 05:45:43 UTC
dev-java/ibm-jdk-bin-1.5.0.7 and dev-java/ibm-jre-bin-1.5.0.7 are in release snapshot.
Comment 9 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2008-05-01 23:09:43 UTC
1.6.0.1 bumped, it wasn't yet stable so no need to.
Comment 10 Robert Buchholz (RETIRED) gentoo-dev 2008-05-20 22:14:21 UTC
Vlastimil, it has been more than six weeks since the IBM alert, and they still have not released 1.4.2 SR11.
Do you have any upstream contact, to ask for an ETA or speed things up?
Comment 11 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2008-05-21 05:48:45 UTC
(In reply to comment #10)
> Vlastimil, it has been more than six weeks since the IBM alert, and they still
> have not released 1.4.2 SR11.

Yeah that seems to be usual there :(

> Do you have any upstream contact, to ask for an ETA or speed things up?

Not myself, and I think nobody else from the Java team neither?
Comment 12 Robert Buchholz (RETIRED) gentoo-dev 2008-06-14 16:27:16 UTC
... finally! :-)
Comment 13 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2008-06-15 23:04:12 UTC
Arches please stabilize:
dev-java/ibm-jre-bin-1.4.2.11
dev-java/ibm-jdk-bin-1.4.2.11

distfiles as usual (comment 3)
Comment 14 Christian Faulhammer (RETIRED) gentoo-dev 2008-06-16 06:41:40 UTC
*** Bug 217442 has been marked as a duplicate of this bug. ***
Comment 15 Christian Faulhammer (RETIRED) gentoo-dev 2008-06-16 06:53:00 UTC
Adding all open blockers of the old bug...what to do about them?
Comment 16 Christian Faulhammer (RETIRED) gentoo-dev 2008-06-16 07:17:43 UTC
Wrong bug for the blockers, sorry for the bugspam.
Comment 17 Christian Faulhammer (RETIRED) gentoo-dev 2008-06-16 07:39:11 UTC
x86 stable
Comment 18 Robert Buchholz (RETIRED) gentoo-dev 2008-06-16 08:38:35 UTC
adding release@
Comment 19 Tobias Scherbaum (RETIRED) gentoo-dev 2008-06-17 16:09:09 UTC
ppc stable
Comment 20 Markus Rothe (RETIRED) gentoo-dev 2008-06-21 19:30:30 UTC
ppc64 stable
Comment 21 Markus Meier gentoo-dev 2008-06-22 11:21:41 UTC
amd64 stable, all arches done.
Comment 22 Robert Buchholz (RETIRED) gentoo-dev 2008-06-24 01:10:37 UTC
glsa ready.
Comment 23 Tobias Heinlein (RETIRED) gentoo-dev 2008-06-26 11:33:18 UTC
GLSA 200806-11