Hi Oracle have fixed it in JDK 1.7.0_09: http://www.oracle.com/technetwork/java/javase/7u9-relnotes-1863279.html http://www.oracle.com/technetwork/topics/security/alerts-086861.html
I suppose it's fixed at the same version of OpenJdk. I've tested openjdk at experimental (7u9-2.3.3-1) and seems to be fixed -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org