cve-2014-3566 cve-2014-6593 in OPEN JDK 8

Moshe Zuisman zuismanm at gmail.com
Fri Sep 25 10:23:11 UTC 2020


Hi.
I am trying to figure out if cve-2014-3566 cve-2014-6593 nad if yes -
starting from which build.
Alan Bateman pointed me to
https://openjdk.java.net/groups/vulnerability/advisories/. But it contains
only a list of fixed vulnerabilities, that were reported at 2019-2020 years.
I have found at https://linux.oracle.com/errata/ELSA-2015-0069.html
that Open JDK 8 for Oracle Linux 6 already contained fix for cve-2014-3566
for example.
But - is there some way, I can be sure that this was included in the
general code base of Open JDK(and not some special branch - ORACLE manages
for their systems), and starting from which build this fix was included?



More information about the build-dev mailing list