From owner-freebsd-java@FreeBSD.ORG Wed Jun 11 19:11:05 2008 Return-Path: Delivered-To: freebsd-java@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 2457E1065691 for ; Wed, 11 Jun 2008 19:11:05 +0000 (UTC) (envelope-from gfranks@hwi.buffalo.edu) Received: from mail.hwi.buffalo.edu (mail.hwi.buffalo.edu [128.205.165.215]) by mx1.freebsd.org (Postfix) with ESMTP id EF4668FC13 for ; Wed, 11 Jun 2008 19:11:04 +0000 (UTC) (envelope-from gfranks@hwi.buffalo.edu) Received: from claven.dhcp.hwi.buffalo.edu (claven [10.1.35.20]) by mail.hwi.buffalo.edu (Postfix) with ESMTP id 2CC5D2B203A for ; Wed, 11 Jun 2008 14:54:33 -0400 (EDT) Received: from 10.1.30.17 ([10.1.30.17]) by claven.dhcp.hwi.buffalo.edu ([10.1.35.20]) with Microsoft Exchange Server HTTP-DAV ; Wed, 11 Jun 2008 18:54:33 +0000 User-Agent: Microsoft-Entourage/11.4.0.080122 Date: Wed, 11 Jun 2008 14:54:01 -0400 From: Geoff Franks To: Message-ID: Thread-Topic: Linux-sun-jdk16 security advisory Thread-Index: AcjL9IL6wXm57jfnEd2v/wAX8g/+ag== Mime-version: 1.0 Content-type: text/plain; charset="US-ASCII" Content-transfer-encoding: 7bit Cc: Subject: Linux-sun-jdk16 security advisory X-BeenThere: freebsd-java@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting Java to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 11 Jun 2008 19:11:05 -0000 I installed linux-sun-jdk16 last week, and it required the jdk-6u3 files. I went to reinstall it today (long story, but I uninstalled it on Friday, and am starting over). However, now it requires the jdk-6u6 files. After I grabbed those, I went to re-install with portinstall, and now I get an error saying that this version has known vulnerabilities: ====================================================================== ===> linux-sun-jdk-1.6.0.06 has known vulnerabilities: => jdk -- jar directory traversal vulnerability. Reference: => Please update your ports tree and try again. *** Error code 1 When I go to the link, it mentions nothing about java 1.6, and nothing over a java 1.5.0p1_1. Is this a new vulnerability that the portaudit page hasn't been updated for, or is this wrongly applying to jdk16? Geoff Franks Sr. Systems Administrator Hauptman Woodward Institute