Security Alert fixes sync/merge into OpenJDK6

Andrew Hughes ahughes at redhat.com
Fri Aug 31 03:27:05 PDT 2012



----- Original Message -----
> On Thu, Aug 30, 2012 at 02:23:09PM -0700, Abhijit Saha wrote:
> > With Oracle security alert [1] went live earlier today, it's time
> > to
> > sync the fixes into OpenJDK6 repositories.
> > 
> > Here's the webrev/changes for this merge/sync.
> >     http://cr.openjdk.java.net/~asaha/6u35-ER-openJDK6/webrev.0/
> > 
> > Please review & approve for this push also comment if any concern.
> 
> This seems to miss the fix for 7162476 to harden the ClassFinder
> just posted for 7, but also applicable to 6.
> 
> Cheers,
> 
> Mark
> 

Also, is there a reason this file wasn't made to use AWTAccessor too:

http://hg.openjdk.java.net/jdk6/jdk6/jdk/file/tip/src/share/classes/sun/awt/ComponentAccessor.java

or just removed entirely?
-- 
Andrew :)

Free Java Software Engineer
Red Hat, Inc. (http://www.redhat.com)

PGP Key: 248BDC07 (https://keys.indymedia.org/)
Fingerprint = EC5A 1F5E C0AD 1D15 8F1F  8F91 3B96 A578 248B DC07



More information about the jdk6-dev mailing list