sun-java6 package from Partner Repo has critical vulnerability

Bug #695774 reported by johnf
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
sun-java6 (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

The current version of sun-java6 from the partner repo is 6.22-0ubuntu1~10.10.

This package needs to be updated to 6.23, as it is vulnerable to CVE-2010-0840 (and a number of others).

Canonical/Ubuntu released a fix for this CVE for the OpenJDK version on the 7th of April of this year (2010):

http://www.ubuntu.com/usn/usn-923-1

CVE References

Revision history for this message
johnf (johnfzc) wrote :

Ok, apparently 6.23 isn't required, 6.22 addresses the most recent CVE for java, http://people.canonical.com/~ubuntu-security/cve/2010/CVE-2010-3574.html

Changed in sun-java6 (Ubuntu):
status: New → Invalid
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.