From owner-freebsd-java@FreeBSD.ORG Tue Oct 9 22:43:16 2007 Return-Path: Delivered-To: freebsd-java@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 7C69316A419 for ; Tue, 9 Oct 2007 22:43:16 +0000 (UTC) (envelope-from peterjeremy@optushome.com.au) Received: from turion.vk2pj.dyndns.org (c220-239-20-82.belrs4.nsw.optusnet.com.au [220.239.20.82]) by mx1.freebsd.org (Postfix) with ESMTP id 0D63C13C457 for ; Tue, 9 Oct 2007 22:43:15 +0000 (UTC) (envelope-from peterjeremy@optushome.com.au) Received: from turion.vk2pj.dyndns.org (localhost.vk2pj.dyndns.org [127.0.0.1]) by turion.vk2pj.dyndns.org (8.14.1/8.14.1) with ESMTP id l99MMngK084006 for ; Wed, 10 Oct 2007 08:22:49 +1000 (EST) (envelope-from peter@turion.vk2pj.dyndns.org) Received: (from peter@localhost) by turion.vk2pj.dyndns.org (8.14.1/8.14.1/Submit) id l99MMnM6084005 for freebsd-java@freebsd.org; Wed, 10 Oct 2007 08:22:49 +1000 (EST) (envelope-from peter) Date: Wed, 10 Oct 2007 08:22:49 +1000 From: Peter Jeremy To: freebsd-java@freebsd.org Message-ID: <20071009222249.GA83921@turion.vk2pj.dyndns.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="Qxx1br4bt0+wmkIi" Content-Disposition: inline X-PGP-Key: http://members.optusnet.com.au/peterjeremy/pubkey.asc User-Agent: Mutt/1.5.16 (2007-06-09) Subject: Recent Java Vulnerabilities X-BeenThere: freebsd-java@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting Java to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 09 Oct 2007 22:43:16 -0000 --Qxx1br4bt0+wmkIi Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable The latest issue of SANS NewsBites notes that Sun have recently released patches for "11 critical vulnerabilities in its Java Runtime Environment (JRE)" affecting Windows, Linux and Solaris. At least some of these vulnerabilities appear to affect FreeBSD as well. Are their plans to update the FreeBSD Java ports? References: http://www.theregister.co.uk/2007/10/05/sun_patches_java/print.html http://www.pcworld.com/article/id,138087-c,softwarebugs/article.html http://blogs.zdnet.com/security/?p=3D562 http://secunia.com/advisories/27009/ http://blogs.sun.com/security/ --=20 Peter Jeremy --Qxx1br4bt0+wmkIi Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (FreeBSD) iD8DBQFHC/85/opHv/APuIcRAqX4AJwIACUdwXUDDJ0e+0jokEkWLixcIgCdHgb4 AFqbf9byuHUPrQiYpXPR1P4= =OCH4 -----END PGP SIGNATURE----- --Qxx1br4bt0+wmkIi--