Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 287490

Summary: <dev-java/ibm-{jdk,jre}-bin-{1.5.0.11,1.6.0.7}: multiple vulnerabilities
Product: Gentoo Security Reporter: Vlastimil Babka (Caster) (RETIRED) <caster>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: java
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.ibm.com/developerworks/java/jdk/alerts/
Whiteboard: ?? [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 252416    
Bug Blocks: 215614    

Description Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2009-10-03 12:39:16 UTC
Several alerts since (including) 10 August 2009 on $URL.
Comment 1 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2009-10-03 12:45:59 UTC
please stabilize ibm-jdk-bin and ibm-jre-bin 1.5.0.10. Distfiles as usual in ssh d.g.o/~caster/tmp/
Comment 2 Brent Baude (RETIRED) gentoo-dev 2009-10-03 15:36:48 UTC
ppc64 done
Comment 3 Christian Faulhammer (RETIRED) gentoo-dev 2009-10-03 22:15:09 UTC
x86 stable
Comment 4 Mounir Lamouri (volkmar) (RETIRED) gentoo-dev 2009-10-15 15:10:48 UTC
ppc stable
Comment 5 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2009-10-19 08:54:48 UTC
1.6.0.6 was released and bumped, ppc/ppc64 please stabilize
Comment 6 Mounir Lamouri (volkmar) (RETIRED) gentoo-dev 2009-10-25 21:58:44 UTC
ppc stable
Comment 7 Markus Meier gentoo-dev 2009-11-09 12:49:50 UTC
amd64 stable
Comment 8 Brent Baude (RETIRED) gentoo-dev 2009-11-17 16:18:45 UTC
ppc64 done
Comment 9 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2009-11-20 10:36:37 UTC
Damn, the alerts changed and now some of the vulnerabilities are fixed only in newer versions (one not yet released).
Anyway, we will likely remove 1.4 as soon as blockers of bug 287615 are stabilized by ppc.
Comment 10 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2009-12-27 13:44:41 UTC
please stabilize ibm-jdk-bin and ibm-jre-bin 1.5.0.11 and 1.6.0.7. Distfiles as usual in
ssh d.g.o/~caster/tmp/
Comment 11 Joe Jezak (RETIRED) gentoo-dev 2009-12-28 06:32:32 UTC
Marked ppc/ppc64 stable.
Comment 12 Christian Faulhammer (RETIRED) gentoo-dev 2009-12-29 18:58:43 UTC
x86 stable
Comment 13 Markus Meier gentoo-dev 2009-12-31 18:16:36 UTC
amd64 stable, all arches done.
Comment 14 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2010-01-22 23:24:56 UTC
1.4 is finally going away (p.mask now), 1.5 and 1.6 are stable, glsa time?
Comment 15 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2010-02-23 22:39:46 UTC
1.4 was removed, but should stay in glsa, right.
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2011-01-02 19:02:34 UTC
This bug is old and information a bit sparse -> I tend to vote no GLSA.
Comment 17 Tim Sammut (RETIRED) gentoo-dev 2011-01-02 19:21:18 UTC
(In reply to comment #16)
> This bug is old and information a bit sparse -> I tend to vote no GLSA.
> 

Agreed. Closing noglsa.