Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 556022 - <dev-java/oracle-{jdk,jre}-bin-1.8.0.51: Multiple vulnerabilities
Summary: <dev-java/oracle-{jdk,jre}-bin-1.8.0.51: Multiple vulnerabilities
Status: RESOLVED DUPLICATE of bug 554886
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://blogs.oracle.com/security/ent...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-07-27 11:43 UTC by Bernd Pachur
Modified: 2015-07-27 12:06 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bernd Pachur 2015-07-27 11:43:39 UTC
+++ This bug was initially created as a clone of Bug #546678 +++

Oracle JRE/JDK 8u51 was released with fixes of critical security fixes. 
The list of vulnerability reports: http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA

Reproducible: Always
Comment 1 Mike Limansky 2015-07-27 11:50:45 UTC
Looks like a duplicate of bug 554886.
Comment 2 James Le Cuirot gentoo-dev 2015-07-27 11:51:03 UTC
Thanks for the duplicate. Next time, don't search based on the version that fixes the vulnerability. You're supposed to put the version *with* the vulnerability in the title.

*** This bug has been marked as a duplicate of bug 554886 ***
Comment 3 Bernd Pachur 2015-07-27 11:53:22 UTC
Jep! You are right!

Sorry, have not found that when searching!
Comment 4 Mike Limansky 2015-07-27 11:57:04 UTC
(In reply to James Le Cuirot from comment #2)
> Thanks for the duplicate. Next time, don't search based on the version that
> fixes the vulnerability. You're supposed to put the version *with* the
> vulnerability in the title.
> 
> *** This bug has been marked as a duplicate of bug 554886 ***

It's a bit weird. I mean it's a common practice for security team to submit bugs with a *range* of broken versions like >x and <=y or, just <y if all previous versions are affected and the fix is already available. Like here:

https://bugs.gentoo.org/buglist.cgi?component=Vulnerabilities&list_id=2857648&query_format=advanced&resolution=---
Comment 5 James Le Cuirot gentoo-dev 2015-07-27 12:06:21 UTC
(In reply to Mike Limansky from comment #4)
> It's a bit weird. I mean it's a common practice for security team to submit
> bugs with a *range* of broken versions like >x and <=y or, just <y if all
> previous versions are affected and the fix is already available.

Fair enough. I realised after posting that what I said was probably inaccurate and I missed the < on the title of this one. Apologies for my dupe rage.