Fwd: [PATCH] Several security issues in lcms

Keith Seitz keiths at redhat.com
Mon Mar 9 11:18:28 PDT 2009


Michal Vyskocil wrote:
> Hi Keith,
> 
> as I found [1] you're the original author of lcms integration in openjdk. As 
> there are some vulnerabilities in it, I used a patches created by SUSE 
> maintainer Standa Brabec [2] and applied them on openjdk-6-src-
> b14-25_nov_2008.tar.gz [3].
> 
> Can you review those patches and add them to openjdk (or icedtea) mainline? 
> The CRD for lcms issues is March 19 (you can contact Tomas Hoger for more 
> detailed information).
> 
> [1] http://mail.openjdk.java.net/pipermail/2d-dev/2008-April/000228.html
> [2] http://pack.suse.cz/sbrabec/restricted/bnc479606/
> [3] http://pack.suse.cz/sbrabec/restricted/bnc479606/Michal_Vyskocil_OpenJDK/
> 
> Best regards
> Michal Vyskocil




More information about the distro-pkg-dev mailing list