Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 352603

Summary: <dev-java/ibm-{jdk,jre}-bin-{1.5.0.12_p3,1.6.0.9}: Multiple vulnerabilities
Product: Gentoo Security Reporter: Vlastimil Babka (Caster) (RETIRED) <caster>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: java, pacho
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.ibm.com/developerworks/java/jdk/alerts/
Whiteboard: B2 [noglsa]
Package list:
Runtime testing required: ---
Bug Depends on: 306583    
Bug Blocks: 215614, 360431    

Description Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2011-01-24 15:59:58 UTC
As usual, the oracle security alerts apply to IBM as well, see "Oracle October 12 2010 SSR" on $URL.
Comment 1 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2011-01-24 16:00:53 UTC
*** Bug 349527 has been marked as a duplicate of this bug. ***
Comment 2 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2011-01-24 16:41:59 UTC
Please stabilize:
dev-java/ibm-jdk-bin-1.5.0.11_p3
dev-java/ibm-jre-bin-1.5.0.11_p3

dev-java/ibm-jdk-bin-1.6.0.9
dev-java/ibm-jre-bin-1.6.0.9

distfiles as usual (ssh d.g.o:~caster/tmp)
Comment 3 Agostino Sarubbo gentoo-dev 2011-01-24 17:30:10 UTC
(In reply to comment #2)
> Please stabilize:
> dev-java/ibm-jdk-bin-1.5.0.11_p3
> dev-java/ibm-jre-bin-1.5.0.11_p3
> 
> dev-java/ibm-jdk-bin-1.6.0.9
> dev-java/ibm-jre-bin-1.6.0.9
> 
> distfiles as usual (ssh d.g.o:~caster/tmp)
> 
small error:


dev-java/ibm-jdk-bin-1.5.0.12_p3
dev-java/ibm-jre-bin-1.5.0.12_p3

I see this in cvs :)
Comment 4 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2011-01-24 21:12:09 UTC
ppc/ppc64 stable
Comment 5 Markos Chandras (RETIRED) gentoo-dev 2011-01-25 10:13:35 UTC
amd64 done
Comment 6 Christian Faulhammer (RETIRED) gentoo-dev 2011-01-25 12:38:06 UTC
stable x86
Comment 7 Tim Sammut (RETIRED) gentoo-dev 2011-01-26 00:20:52 UTC
Thanks, folks.

I've rated this one B2 based on the high (too high?) CVSS scores on at $URL. Added to existing GLSA request.