-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 16 Feb 2011 21:37:38 +0100 Source: sun-java6 Binary: sun-java6-jre sun-java6-bin sun-java6-plugin ia32-sun-java6-bin ia32-sun-java6-plugin sun-java6-fonts sun-java6-jdk sun-java6-demo sun-java6-source sun-java6-doc sun-java6-javadb Architecture: i386 Version: 6-24-0lenny1 Distribution: oldstable Urgency: low Maintainer: Matthias Klose Changed-By: Torsten Werner Description: ia32-sun-java6-bin - Sun Java(TM) Runtime Environment (JRE) 6 (32-bit) ia32-sun-java6-plugin - The Java(TM) Plug-in, Java SE 6 (32-bit) sun-java6-bin - Sun Java(TM) Runtime Environment (JRE) 6 (architecture dependent sun-java6-demo - Sun Java(TM) Development Kit (JDK) 6 demos and examples sun-java6-doc - Sun JDK(TM) Documention -- integration installer sun-java6-fonts - Lucida TrueType fonts (from the Sun JRE) sun-java6-javadb - Java(TM) DB, Sun Microsystems' distribution of Apache Derby sun-java6-jdk - Sun Java(TM) Development Kit (JDK) 6 sun-java6-jre - Sun Java(TM) Runtime Environment (JRE) 6 (architecture independen sun-java6-plugin - The Java(TM) Plug-in, Java SE 6 sun-java6-source - Sun Java(TM) Development Kit (JDK) 6 source files Closes: 613741 Changes: sun-java6 (6-24-0lenny1) oldstable; urgency=low . * New upstream release (Closes: #613741) * SECURITY UPDATE: multiple upstream vulnerabilities. Upstream fixes: - (CVE-2010-4476): Java Runtime Environment hangs when converting "2.2250738585072012e-308" to a binary floating-point number. - (CVE-2010-4452): Oracle Java XGetSamplePtrFromSnd Remote Code Execution Vulnerability - (CVE-2010-4454): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4462): XGetSamplePtrFromSnd Remote Code Execution Vulnerability - (CVE-2010-4463): Webstart Trusted JNLP Extension Remote Code Execution Vulnerability - (CVE-2010-4465): Swing timer-based security manager bypass - (CVE-2010-4467): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4469): Hotspot backward jsr heap corruption - (CVE-2010-4473): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4422): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4451): Vulnerability allows successful unauthenticated network attacks via HTTP. - (CVE-2010-4466): Runtime NTLM Authentication Information Leakage Vulnerability - (CVE-2010-4470): JAXP untrusted component state manipulation - (CVE-2010-4471): Java2D font-related system property leak - (CVE-2010-4447): Vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4475): vulnerability allows successful unauthenticated network attacks via multiple protocols. - (CVE-2010-4468): DNS cache poisoning by untrusted applets - (CVE-2010-4450): Launcher incorrect processing of empty library path entries - (CVE-2010-4448): DNS cache poisoning by untrusted applets - (CVE-2010-4472): Untrusted code allowed to replace DSIG/C14N implementation - (CVE-2010-4474): Easily exploitable vulnerability requiring logon to Operating System. Checksums-Sha1: 0e3480c75ef09190381ed1d1e92bd7d620345496 29973478 sun-java6-bin_6-24-0lenny1_i386.deb 4ecfe44771aa4ab51393117cd2ce85c67164a29d 1948 sun-java6-plugin_6-24-0lenny1_i386.deb 2a3c3d5c701b27e031f69b90445c4d75556ae425 20222698 sun-java6-jdk_6-24-0lenny1_i386.deb f8b5e4d2d6e9877783a25cef398d0ecb4948af3c 12157428 sun-java6-demo_6-24-0lenny1_i386.deb Checksums-Sha256: 1e9985f59cfbf27ee399cc3e278d71cdf24128ff426807faf3f4bb61bf3701a7 29973478 sun-java6-bin_6-24-0lenny1_i386.deb 5b43db79764d70bfca43daeefe8cb4bec51522c0bffccb8d8310248e1b9df83b 1948 sun-java6-plugin_6-24-0lenny1_i386.deb ad06e653b58e5702462bfd4f3b28d176029b57e7ed2815a2575f6d077aca03c4 20222698 sun-java6-jdk_6-24-0lenny1_i386.deb ecc8df2d2c532888452e28f19f927920c5f05f95d423590a50b48c00983b9c75 12157428 sun-java6-demo_6-24-0lenny1_i386.deb Files: e2dbd41a908714b7465c762377d237d2 29973478 non-free/libs optional sun-java6-bin_6-24-0lenny1_i386.deb 2b69d03176d9f6af3d2a5b42a24394a7 1948 non-free/web optional sun-java6-plugin_6-24-0lenny1_i386.deb 413213d4483e1ac923997c253940a97b 20222698 non-free/devel optional sun-java6-jdk_6-24-0lenny1_i386.deb eb7c37ee6c6d467d42a7aeb52cc97eb4 12157428 non-free/devel optional sun-java6-demo_6-24-0lenny1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk1qqNcACgkQfY3dicTPjsO4MwCgiP3z8Khl9okm4vgKbeWPGQMT 5OUAoILhKYTUuRdKxGXvR+HAVGFtOy2s =CnWp -----END PGP SIGNATURE-----