-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 16 Feb 2011 21:37:38 +0100 Source: sun-java6 Binary: sun-java6-jre sun-java6-bin sun-java6-plugin ia32-sun-java6-bin ia32-sun-java6-plugin sun-java6-fonts sun-java6-jdk sun-java6-demo sun-java6-source sun-java6-doc sun-java6-javadb Architecture: source amd64 all Version: 6-24-0lenny1 Distribution: oldstable Urgency: low Maintainer: Matthias Klose Changed-By: Torsten Werner Description: ia32-sun-java6-bin - Sun Java(TM) Runtime Environment (JRE) 6 (32-bit) ia32-sun-java6-plugin - The Java(TM) Plug-in, Java SE 6 (32-bit) sun-java6-bin - Sun Java(TM) Runtime Environment (JRE) 6 (architecture dependent sun-java6-demo - Sun Java(TM) Development Kit (JDK) 6 demos and examples sun-java6-doc - Sun JDK(TM) Documention -- integration installer sun-java6-fonts - Lucida TrueType fonts (from the Sun JRE) sun-java6-javadb - Java(TM) DB, Sun Microsystems' distribution of Apache Derby sun-java6-jdk - Sun Java(TM) Development Kit (JDK) 6 sun-java6-jre - Sun Java(TM) Runtime Environment (JRE) 6 (architecture independen sun-java6-plugin - The Java(TM) Plug-in, Java SE 6 sun-java6-source - Sun Java(TM) Development Kit (JDK) 6 source files Closes: 613741 Changes: sun-java6 (6-24-0lenny1) oldstable; urgency=low . * New upstream release (Closes: #613741) * SECURITY UPDATE: multiple upstream vulnerabilities. Upstream fixes: - (CVE-2010-4476): Java Runtime Environment hangs when converting "2.2250738585072012e-308" to a binary floating-point number. - (CVE-2010-4452): Oracle Java XGetSamplePtrFromSnd Remote Code Execution Vulnerability - (CVE-2010-4454): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4462): XGetSamplePtrFromSnd Remote Code Execution Vulnerability - (CVE-2010-4463): Webstart Trusted JNLP Extension Remote Code Execution Vulnerability - (CVE-2010-4465): Swing timer-based security manager bypass - (CVE-2010-4467): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4469): Hotspot backward jsr heap corruption - (CVE-2010-4473): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4422): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4451): Vulnerability allows successful unauthenticated network attacks via HTTP. - (CVE-2010-4466): Runtime NTLM Authentication Information Leakage Vulnerability - (CVE-2010-4470): JAXP untrusted component state manipulation - (CVE-2010-4471): Java2D font-related system property leak - (CVE-2010-4447): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4475): vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4468): DNS cache poisoning by untrusted applets - (CVE-2010-4450): Launcher incorrect processing of empty library path entries - (CVE-2010-4448): DNS cache poisoning by untrusted applets - (CVE-2010-4472): Untrusted code allowed to replace DSIG/C14N implementation - (CVE-2010-4474): Easily exploitable vulnerability requiring logon to Operating System. Checksums-Sha1: 26cb528052c0a76f1afef576086d93b45ad89a54 1702 sun-java6_6-24-0lenny1.dsc f51f1d65555e43b1fd3d4dead86e6022ff215ec0 167431099 sun-java6_6-24.orig.tar.gz 99ec56efe4794ee2109c2314807651ce12a3982b 80776 sun-java6_6-24-0lenny1.diff.gz 9b271d0107eb88ab87c878962d2bb7a744de71ad 28161828 sun-java6-bin_6-24-0lenny1_amd64.deb 9b4b1e81f4504fb926075391a63063df488c300a 1954 sun-java6-plugin_6-24-0lenny1_amd64.deb 28b301e5e349561ba5ceea5bb8f00ef8b4fb2674 29973352 ia32-sun-java6-bin_6-24-0lenny1_amd64.deb 2f9353bc952a12e0df7242a67d9791b93dde785c 20398012 sun-java6-jdk_6-24-0lenny1_amd64.deb 0e5ad6cd59373201ad71646db4466c93ac01b325 12162586 sun-java6-demo_6-24-0lenny1_amd64.deb 742fa88bff5697e4c417cd0bacbdb64070ee8b96 6498152 sun-java6-jre_6-24-0lenny1_all.deb 4ca0ee2220a23197949f58388d84c8b9fc8a4a1f 1854 sun-java6-fonts_6-24-0lenny1_all.deb 6d4dd8ff7437edf60f9def5b21c729c8cb1d2907 17951836 sun-java6-source_6-24-0lenny1_all.deb d4434ad887116046ddaa4259fb3b33487de40386 35442 sun-java6-doc_6-24-0lenny1_all.deb 3387daf2841b371d423a691aa5744444bdc6cae5 10788130 sun-java6-javadb_6-24-0lenny1_all.deb Checksums-Sha256: 8cf2e3d798dd5ee3071ff05f36f894c2450a45c74d7df6198d17cbba10e8c57f 1702 sun-java6_6-24-0lenny1.dsc 982fad10cf584fa55781e7bef432fbf69e917a6975cb0a34f0c511ec651cd98a 167431099 sun-java6_6-24.orig.tar.gz 1b1db0ac8997431670afe62501b2cdeb3c0e04f9e8b437712c4f4fb711977162 80776 sun-java6_6-24-0lenny1.diff.gz 7182c600bae0ee092d8321b35da86481ab5773f2bf73a54a40d498e284b1f260 28161828 sun-java6-bin_6-24-0lenny1_amd64.deb 38ae017b05ced48f9c3c1479559ee765882c3a605021c3f6c477f9209fbf86e6 1954 sun-java6-plugin_6-24-0lenny1_amd64.deb 19a09f8c2609cdfdd16427afbe0ee543da9e4d260909b6598766ae06c70201e7 29973352 ia32-sun-java6-bin_6-24-0lenny1_amd64.deb 312c632f746fd293c3b2f4f61b898e7a45d788c3ec1849acb1f1ae76f4faabaf 20398012 sun-java6-jdk_6-24-0lenny1_amd64.deb 1778b53cbc255db3cb33b7695c6c6b6a6bd32134987868b765b8fa23f0a21539 12162586 sun-java6-demo_6-24-0lenny1_amd64.deb 6223dbde0ff1793857d06ffe62a18c29cd5f33fce2f4ea348e23ae1782489a3a 6498152 sun-java6-jre_6-24-0lenny1_all.deb 51a6b175421899b8a90268c28ba8c4253b735714ac9dc6db2dbd0b5892bef508 1854 sun-java6-fonts_6-24-0lenny1_all.deb 037466d10d0de8c48e22a53765ddc6c097eed2b236e373cd56122b3abddea387 17951836 sun-java6-source_6-24-0lenny1_all.deb 3607b597ab33f6f8d7471f1853578e8c81e5757d830842b1c461017fd3fd74d9 35442 sun-java6-doc_6-24-0lenny1_all.deb 7a6cb92657a93a09df4e7417da83f158e43876ef6f5b4e98124fead54a6b5634 10788130 sun-java6-javadb_6-24-0lenny1_all.deb Files: d68ea69d37b73d6d18ea6f941b35dd26 1702 non-free/devel optional sun-java6_6-24-0lenny1.dsc 3cd597b7d8a15ce1a235f36e4235d0c4 167431099 non-free/devel optional sun-java6_6-24.orig.tar.gz db2c41fdc63407643d9b09dd78c201d7 80776 non-free/devel optional sun-java6_6-24-0lenny1.diff.gz ffc49a4b07e90c7bd3e601d991a31eef 28161828 non-free/libs optional sun-java6-bin_6-24-0lenny1_amd64.deb 14804a7f6978c8c8aa28f81e55f417e7 1954 non-free/web optional sun-java6-plugin_6-24-0lenny1_amd64.deb 7aeaec4fc0247206e7d63357f9cbc5ef 29973352 non-free/libs optional ia32-sun-java6-bin_6-24-0lenny1_amd64.deb f8b6d821486c23755865c5e0ee2a990a 20398012 non-free/devel optional sun-java6-jdk_6-24-0lenny1_amd64.deb 93d3a5efca1cc1596ce18a10ed9c1008 12162586 non-free/devel optional sun-java6-demo_6-24-0lenny1_amd64.deb 0b041b6c4ab310594bc79b571649e2b6 6498152 non-free/libs optional sun-java6-jre_6-24-0lenny1_all.deb 73e3bae950efb074b1b5c1923e390a9b 1854 non-free/x11 optional sun-java6-fonts_6-24-0lenny1_all.deb 6529e327dd39767d51d01144a639fae7 17951836 non-free/devel optional sun-java6-source_6-24-0lenny1_all.deb d7a4ce549a1cec293c7c8f52c22b58f6 35442 non-free/doc optional sun-java6-doc_6-24-0lenny1_all.deb 9ba0a2a9e8b96542efff2d8ca512f6c3 10788130 non-free/libs optional sun-java6-javadb_6-24-0lenny1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk1qp3MACgkQfY3dicTPjsPlZQCeKIC7BZ8u92olqnG7PSDLL7ih 5jAAoILm0Wu+gzrRF+Q7YRck/y6cZ8I5 =bWS0 -----END PGP SIGNATURE-----