[PATCH] jdk7u95-b00 retro-active security patch review

Andrew Hughes gnu.andrew at redhat.com
Wed Jan 27 23:23:49 UTC 2016


We have a new release of IcedTea (http://bitly.com/it20604) and a new OpenJDK
7 release, u95-b00, to go with it. This is made from the current state of the 
penJDK 7u repositories plus backports of the new security fixes included in 8u71.

The tarball is available here:

https://java.net/projects/openjdk7/downloads/download/openjdk7u95-b00.tar.xz

SHA256 checksum:

e942e9d9d622418614fdb89b45722f9f0accd6cffa196d21ca57f59bfa0054ed  openjdk7u95-b00.tar.xz

Changes since u91-b02:

* Security fixes
  - S8059054, CVE-2016-0402: Better URL processing
  - S8130710, CVE-2016-0448: Better attributes processing
  - S8132210: Reinforce JMX collector internals
  - S8132988: Better printing dialogues
  - S8133962, CVE-2016-0466: More general limits
  - S8137060: JMX memory management improvements
  - S8139012: Better font substitutions
  - S8139017, CVE-2016-0483: More stable image decoding
  - S8140543, CVE-2016-0494: Arrange font actions
  - S8143185: Cleanup for handling proxies
  - S8143941, CVE-2015-8126, CVE-2015-8472: Update splashscreen displays
  - S8144773, CVE-2015-7575: Further reduce use of MD5 (SLOTH)
* Other changes
  - S7167988: PKIX CertPathBuilder in reverse mode doesn't work if more than one trust anchor is specified
  - S8068761: [TEST_BUG] java/nio/channels/ServerSocketChannel/AdaptServerSocket.java failed with SocketTimeoutException
  - S8074068: Cleanup in src/share/classes/sun/security/x509/
  - S8075773: jps running as root fails after the fix of JDK-8050807
  - S8081297: SSL Problem with Tomcat
  - S8131181: Increment minor version of HSx for 7u95 and initialize the build number
  - S8132082: Let OracleUcrypto accept RSAPrivateKey
  - S8134605: Partial rework of the fix for 8081297
  - S8134861: XSLT: Extension func call cause exception if namespace URI contains partial package name
  - S8135307: CompletionFailure thrown when calling FieldDoc.type, if the field's type is missing
  - S8138716: (tz) Support tzdata2015g
  - S8140244: Port fix of JDK-8075773 to MacOSX
  - S8141213: [Parfait]Potentially blocking function GetArrayLength called in JNI critical region at line 239 of jdk/src/share/native/sun/awt/image/jpeg/jpegdecoder.c in function GET_ARRAYS
  - S8141287: Add MD5 to jdk.certpath.disabledAlgorithms - Take 2
  - S8142928: [TEST_BUG] sun/security/provider/certpath/ReverseBuilder/ReverseBuild.java 8u71 failure
  - S8143132: L10n resource file translation update
  - S8144955: Wrong changes were pushed with 8143942
  - S8145551: Test failed with Crash for Improved font lookups
  - S8147466: Add -fno-strict-overflow to IndicRearrangementProcessor{,2}.cpp

Webrevs for the new changes:
 
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/root/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/corba/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/jaxp/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/jaxws/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/hotspot/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/jdk/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/langtools/

Once approved, I'll push these to the OpenJDK 7 repository.

Thanks,
-- 
Andrew :)

Senior Free Java Software Engineer
Red Hat, Inc. (http://www.redhat.com)

PGP Key: ed25519/35964222 (hkp://keys.gnupg.net)
Fingerprint = 5132 579D D154 0ED2 3E04  C5A0 CFDA 0F9B 3596 4222




More information about the jdk7u-dev mailing list