[PATCH] jdk7u95-b00 retro-active security patch review
Andrew Hughes
gnu.andrew at redhat.com
Wed Jan 27 23:23:49 UTC 2016
We have a new release of IcedTea (http://bitly.com/it20604) and a new OpenJDK
7 release, u95-b00, to go with it. This is made from the current state of the
penJDK 7u repositories plus backports of the new security fixes included in 8u71.
The tarball is available here:
https://java.net/projects/openjdk7/downloads/download/openjdk7u95-b00.tar.xz
SHA256 checksum:
e942e9d9d622418614fdb89b45722f9f0accd6cffa196d21ca57f59bfa0054ed openjdk7u95-b00.tar.xz
Changes since u91-b02:
* Security fixes
- S8059054, CVE-2016-0402: Better URL processing
- S8130710, CVE-2016-0448: Better attributes processing
- S8132210: Reinforce JMX collector internals
- S8132988: Better printing dialogues
- S8133962, CVE-2016-0466: More general limits
- S8137060: JMX memory management improvements
- S8139012: Better font substitutions
- S8139017, CVE-2016-0483: More stable image decoding
- S8140543, CVE-2016-0494: Arrange font actions
- S8143185: Cleanup for handling proxies
- S8143941, CVE-2015-8126, CVE-2015-8472: Update splashscreen displays
- S8144773, CVE-2015-7575: Further reduce use of MD5 (SLOTH)
* Other changes
- S7167988: PKIX CertPathBuilder in reverse mode doesn't work if more than one trust anchor is specified
- S8068761: [TEST_BUG] java/nio/channels/ServerSocketChannel/AdaptServerSocket.java failed with SocketTimeoutException
- S8074068: Cleanup in src/share/classes/sun/security/x509/
- S8075773: jps running as root fails after the fix of JDK-8050807
- S8081297: SSL Problem with Tomcat
- S8131181: Increment minor version of HSx for 7u95 and initialize the build number
- S8132082: Let OracleUcrypto accept RSAPrivateKey
- S8134605: Partial rework of the fix for 8081297
- S8134861: XSLT: Extension func call cause exception if namespace URI contains partial package name
- S8135307: CompletionFailure thrown when calling FieldDoc.type, if the field's type is missing
- S8138716: (tz) Support tzdata2015g
- S8140244: Port fix of JDK-8075773 to MacOSX
- S8141213: [Parfait]Potentially blocking function GetArrayLength called in JNI critical region at line 239 of jdk/src/share/native/sun/awt/image/jpeg/jpegdecoder.c in function GET_ARRAYS
- S8141287: Add MD5 to jdk.certpath.disabledAlgorithms - Take 2
- S8142928: [TEST_BUG] sun/security/provider/certpath/ReverseBuilder/ReverseBuild.java 8u71 failure
- S8143132: L10n resource file translation update
- S8144955: Wrong changes were pushed with 8143942
- S8145551: Test failed with Crash for Improved font lookups
- S8147466: Add -fno-strict-overflow to IndicRearrangementProcessor{,2}.cpp
Webrevs for the new changes:
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/root/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/corba/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/jaxp/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/jaxws/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/hotspot/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/jdk/
http://cr.openjdk.java.net/~andrew/openjdk7/20160119/langtools/
Once approved, I'll push these to the OpenJDK 7 repository.
Thanks,
--
Andrew :)
Senior Free Java Software Engineer
Red Hat, Inc. (http://www.redhat.com)
PGP Key: ed25519/35964222 (hkp://keys.gnupg.net)
Fingerprint = 5132 579D D154 0ED2 3E04 C5A0 CFDA 0F9B 3596 4222
More information about the jdk7u-dev
mailing list