From owner-freebsd-java@FreeBSD.ORG Thu Feb 24 20:20:38 2011 Return-Path: Delivered-To: freebsd-java@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 4CFD4106566B for ; Thu, 24 Feb 2011 20:20:38 +0000 (UTC) (envelope-from Alexander.Zenger@f-i-ts.de) Received: from smx2.f-i-ts.de (smx2.f-i-ts.de [212.34.66.102]) by mx1.freebsd.org (Postfix) with ESMTP id 0A5418FC18 for ; Thu, 24 Feb 2011 20:20:36 +0000 (UTC) Received: from fits-stmail1.isp.fits (fits-stmail1.isp.fits [172.16.144.55]) by smx2.f-i-ts.de (Postfix) with SMTP id C42FA5E9B0 for ; Thu, 24 Feb 2011 21:05:21 +0100 (CET) Received: from exchange-fits.izb.private ([172.20.239.180]) by fits-stmail1.isp.fits (Totemo SMTP Server) with SMTP ID 250 for ; Thu, 24 Feb 2011 21:05:21 +0100 (CET) Received: from izpsimsx03.asp.izb ([172.20.239.176]) by IZPSIMSX02.asp.izb ([172.20.239.180]) with mapi; Thu, 24 Feb 2011 21:05:21 +0100 From: "Zenger, Alexander" To: "'freebsd-java@FreeBSD.org'" Date: Thu, 24 Feb 2011 21:05:20 +0100 Thread-Topic: Question Update Java Security Updates Thread-Index: AcvUXiCejlTY9o8qQJuuSwarcz9xDQ== Message-ID: Accept-Language: de-DE Content-Language: de-DE X-MS-Has-Attach: X-MS-TNEF-Correlator: acceptlanguage: de-DE Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Cc: Subject: Question Update Java Security Updates X-BeenThere: freebsd-java@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting Java to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 24 Feb 2011 20:20:38 -0000 Hi, I was wondering how the security updates from the Oracle Java are integrate= d in FreeBSD Java. I couldn't find any information related to that on the FreeBSD Java site, a= nd I also didn't see any portaudit entries, but I think there must be some.=20 For example CVE-2010-4476 "Converting the deciaml value '2.2250738585072012= e-308'" causes a dos". There were several CVE's fixed with the last Release, see here: http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.ht= ml Best Regards alex