[Bug 126059] Re: Java has Huge Security Vulnerability, should be updated to 6update2

2007-08-13 Thread Alvin Thompson
you're right, of course. i was griping about the lack of a backport on the wrong bug report. -- Java has Huge Security Vulnerability, should be updated to 6update2 https://bugs.launchpad.net/bugs/126059 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct

[Bug 126059] Re: Java has Huge Security Vulnerability, should be updated to 6update2

2007-08-13 Thread Tom Marble
@Alvin The sources for the DLJ bundles against which this bug was filed are not available under the GPL. We sincerely hope to have a 100% GPL version of OpenJDK (JDK 7 alpha) available as soon as possible -- with help from the community. As doko mentions JDK6u2 has been updated to the Ubuntu arc

[Bug 126059] Re: Java has Huge Security Vulnerability, should be updated to 6update2

2007-08-13 Thread Alvin Thompson
the sources are still available from Sun, correct? while it certainly is convenient to package the sources with the binary, it's not a requirement. the sources just must be readily available, correct? and it's certainly not a good reason to leave a broken/insecure version of java in the distribut

[Bug 126059] Re: Java has Huge Security Vulnerability, should be updated to 6update2

2007-07-18 Thread VF
So Feisty users are being left with the security vulnerability? I know it's a multiverse package but with the way Sun/Canonical, were trumpeting the partnership when Feisty was released, I expected a bit more support than your average multiverse package.. -- Java has Huge Security Vulnerability,

[Bug 126059] Re: Java has Huge Security Vulnerability, should be updated to 6update2

2007-07-18 Thread Matthias Klose
sun-java6 (6-02-0ubuntu1) gutsy; urgency=low * New upstream bug fix release. Closes LP: #126059. * WARNING: Remove the sun-java6-db package. Apparently the javadb sources are not included in the DLJ bundles while these are still included in the standard bundles. The fix will most like

[Bug 126059] Re: Java has Huge Security Vulnerability, should be updated to 6update2

2007-07-18 Thread Matthias Klose
while the update is now available under the DLJ, the bundles are missing components; waiting for feedback from Sun -- Java has Huge Security Vulnerability, should be updated to 6update2 https://bugs.launchpad.net/bugs/126059 You received this bug notification because you are a member of Ubuntu Bu

[Bug 126059] Re: Java has Huge Security Vulnerability, should be updated to 6update2

2007-07-17 Thread Conrad Knauer
I'm going to set the Status to "Confirmed"; as per http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-102934-1 --- A buffer overflow vulnerability in the image parsing code in the Java Runtime Environment may allow an untrusted applet or application to elevate its privileges. For exam

[Bug 126059] Re: Java has Huge Security Vulnerability, should be updated to 6update2

2007-07-16 Thread Kees Cook
** Visibility changed to: Public -- Java has Huge Security Vulnerability, should be updated to 6update2 https://bugs.launchpad.net/bugs/126059 You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. -- ubuntu-bugs mailing list ubuntu-bugs@lists.