Thanks for the alert. I have updated my JRE on my OSol 2010.03 (though it was a bit tricky and involved manual folder rename/move). The box is used for production as a web and ftp server.

This issue have forced me to look again at OpenSUSE - I am thinking of migrating to it while OpenIndiana is not yet matured enough and not yet receiving critical security patches in time. There is no Java at all by default in OpenSUSE (and maybe in all other Linuxes). No Java, no (this) vulnerability. Other security holes are patched in time (I think).

No Java, no ZFS, no a lot other great stuff... But it will do web and ftp for me... Still with OSol yet :) Cannot just waste the favorite OS.

Dmitry.


On 18.02.2011 6:29, Ivan Wang wrote:
Hi list,

Not sure if the vulnerability does actually affect solaris based systems.
But Oracle advises to update JRE/JDK to 6u24 to pick up patches
preventing remote exploit.

Here is the link:
http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.html

Any plan to bump Java version in oi ips repo?

Cheers,
Ivan.

_______________________________________________
OpenIndiana-discuss mailing list
[email protected]
http://openindiana.org/mailman/listinfo/openindiana-discuss


_______________________________________________
OpenIndiana-discuss mailing list
[email protected]
http://openindiana.org/mailman/listinfo/openindiana-discuss

Reply via email to