RE: Does JDK7 security hole affect OpenJDK6?

2013-01-17 Thread Deniz Akcal
Thanks for confirming. > Date: Thu, 17 Jan 2013 12:22:49 + > From: a...@redhat.com > To: denizak...@hotmail.com > CC: a.kucka...@ping.de; debian-j...@lists.debian.org; > debian-security@lists.debian.org > Subject: Re: Does JDK7 security hole affect OpenJDK6? > > On 01/17/2013 11:58 AM, Deniz

Re: Does JDK7 security hole affect OpenJDK6?

2013-01-17 Thread Andrew Haley
On 01/17/2013 11:58 AM, Deniz Akcal wrote: > I read somewhere (I think it was on Techrepublic but, I'm not sure) that the > answer to that was no (as in that popular security hole does not affect > OpenJDK 6). You should get confirmation from someone that knows more about > this, though. I can

RE: Does JDK7 security hole affect OpenJDK6?

2013-01-17 Thread Deniz Akcal
I read somewhere (I think it was on Techrepublic but, I'm not sure) that the answer to that was no (as in that popular security hole does not affect OpenJDK 6). You should get confirmation from someone that knows more about this, though. > Date: Thu, 17 Jan 2013 11:22:28 +0100 > From: a.kucka...

Re: Does JDK7 security hole affect OpenJDK6?

2013-01-17 Thread Andreas Kuckartz
I found CVE-2013-0422 on the TODO list: https://security-tracker.debian.org/tracker/status/todo Cheers, Andreas --- Andreas Kuckartz: > David Gerard: >> I would assume the recent JDK7 hole would also affect OpenJDK7, given >> they're pretty much the same codebase. >> >> But OpenJDK6 is based on O

Re: Does JDK7 security hole affect OpenJDK6?

2013-01-17 Thread Andreas Kuckartz
David Gerard: > I would assume the recent JDK7 hole would also affect OpenJDK7, given > they're pretty much the same codebase. > > But OpenJDK6 is based on OpenJDK7, cut down to pass JCK6. Has anyone > checked if OpenJDK6 is vulnerable? CERT states this: "Systems Affected Any system using Oracl