Summary: | dev-java/icedtea-bin-3.0.0_* is detected as vulnerable by glsa-check -t | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sylvain CANOINE <canouble> |
Component: | GLSA Errors | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | creideiki+gentoo-bugzilla, java |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | AMD64 | ||
OS: | Linux | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
Sylvain CANOINE
2016-03-04 11:14:42 UTC
I've just been alerted to this and it now also affects GLSA 201603-14. icedtea-3 is actually the latest version (for Java 8) because we've switched to match upstream's versioning scheme instead of our own weird one. Apart from this issue, it hasn't been a problem because we always depend on JVMs using SLOTs. Since I'm currently trying to push icedtea-3 as the new big thing right now, I'd really like this fixed! I don't like touching GLSAs myself though so please take a look. After discussing this with b-man and trying it locally, it looks like adding this is the way to go. <unaffected range="lt">6</unaffected> We don't have icedtea-3 in the tree yet, only icedtea-bin-3, but it will be coming so don't forget to add it for both. dev-java/icedtea-3.0.0 is now in the tree and is also affected by this bug. I pinged b-man about it a while ago and he said he wasn't allowed to modify the GLSA files yet. Obviously I'm not allowed either but I don't care, security team, if you don't make the changes this coming week, I will do it myself. commit b47115cd45a31ae205124ceb2e64da40905eeadd Author: Tobias Heinlein <keytoaster@gentoo.org> Date: Tue Apr 19 23:37:16 2016 +0200 IcedTea GLSAs: Add unaffected < 6 due to new versioning scheme (bug 576428). The problem reappeared with 201606-18 and dev-java/icedtea-bin-3.1.0 : # glsa-check -vt all This system is affected by the following GLSAs: [A] means this GLSA was marked as applied (injected), [U] means the system is not affected and [N] indicates that the system might be affected. 201606-18 [N] [remote ] IcedTea: Multiple vulnerabilities ( dev-java/icedtea-bin-3.1.0 ) # (In reply to Sylvain CANOINE from comment #6) > The problem reappeared with 201606-18 and dev-java/icedtea-bin-3.1.0 : Reopening. Guys, let's keep on top of this, please! 201606-18 also mentions just icedtea-bin, not icedtea, which is equally affected. Issue with GLSA-201606-18 is fixed in bug #591346 |