Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 183580 - dev-java/{sun-jdk|sun-jre-bin}-1.4.2.14 affected by GLSA 200705-23
Summary: dev-java/{sun-jdk|sun-jre-bin}-1.4.2.14 affected by GLSA 200705-23
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.gentoo.org/security/en/gls...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks: java-security
  Show dependency tree
 
Reported: 2007-06-28 23:51 UTC by Vlastimil Babka (Caster) (RETIRED)
Modified: 2008-04-17 23:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2007-06-28 23:51:04 UTC
+++ This bug was initially created as a clone of Bug #182824 +++
http://www.gentoo.org/security/en/glsa/glsa-200705-23.xml

Bug 182824 was about blackdown-jdk but I could reproduce it with sun-jdk-1.4 too.

Results with 1.4.2.14 with badicc.jpg from http://scary.beasts.org/security/CESA-2006-004.html

#  SIGSEGV (0xb) at pc=0xb7ea50dc, pid=20387, tid=3085122240
#
# Java VM: Java HotSpot(TM) Client VM (1.4.2_14-b05 mixed mode)
# Problematic frame:
# C  [libc.so.6+0x710dc]  memcpy+0x1c

Results with recently added 1.4.2.15:

Exception in thread "main" java.lang.IllegalArgumentException: Invalid ICC Profile Data
        at java.awt.color.ICC_Profile.getInstance(ICC_Profile.java:709)


Apparently they fixed it, safe java exception instead of segfault. Although I didn't find any relevant bug in 1.4.2.15 changelog or advisory from Sun. But maybe we can assume it's fixed, get it stable and glsa'd.
Comment 1 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2007-07-01 11:13:40 UTC
OK got it confirmed from SUN:

http://sunsolve.sun.com/search/document.do?assetkey=1-26-102934-1

x86 please stabilize:
dev-java/sun-jdk-1.4.2.15
dev-java/sun-jre-bin-1.4.2.15
Comment 2 Christian Faulhammer (RETIRED) gentoo-dev 2007-07-02 18:55:51 UTC
x86 stable, last arch, changing status to glsa?
Comment 3 Matt Drew (RETIRED) gentoo-dev 2007-07-02 21:50:12 UTC
I vote yes for GLSA.
Comment 4 Sune Kloppenborg Jeppesen gentoo-dev 2007-07-15 07:24:19 UTC
Voting YES.
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2008-04-17 23:44:30 UTC
GLSA 200804-20, sorry for the long delay.