Movatterモバイル変換


[0]ホーム

URL:


Country
Contact Sales

Update Release Notes

Changes in 1.6.0_17 (6u17)

The full internal version number for this update release is 1.6.0_17-b04 (where "b" means "build"). The external version number is 6u17.

OlsonData 2009m

6u17 contains Olson time zone data version 2009m. For more information, refer toTimezone Data Versions in the JRE Software .

Security Baseline

6u17 specifies the following security baselines for use with Java Plug-in technology:

JRE Family VersionJava SESecurity BaselineJava SE for BusinessSecurity Baseline
61.6.0_171.6.0_17
5.01.5.0_221.5.0_22
1.4.21.4.2_191.4.2_24

For more information about the security baseline, seeDeploying Java Applets With Family JRE Versions in Java Plug-in for Internet Explorer .

Root Certificates

Root Certificates are included in this release.

  • Added one new root certificate for SECOM. (Refer to6872579.)
  • Added one new root certificate for GlobalSign. (Refer to6860447.)

Blacklist Entries

There are no new blacklist entries in this update release.

Bug Fixes

This release contains fixes for one or more security vulnerabilities.

Bug fixes for vulnerabilities are listed in the following table.

BugIdCategorySubcategoryDescription
6631533javaclasses_2dICC_Profile allows detecting if some files exist
6815780javaclasses_2dTrueType font parsing crash when stressing Sun Bug6751322 test case
6822057javaclasses_2dX11 and Win32GraphicsDevice don't clone arrays returned from getConfigurations()
6862969javaclasses_2dJPEG JFIF Decoder issue
6862970javaclasses_2dImage Color Profile parsing issue
6872357javaclasses_2dJRE AWT setDifflCM vulnerable to Stack Overflow
6872358javaclasses_2dJRE AWT setBytePixels vulnerable to Heap Overflow
6664512javaclasses_awtComponent and [Default]KeyboardFocusManager pass security sensitive objects to loggers
6636650javaclasses_lang(cl) Resurrected ClassLoaders can still have children
6861062javaclasses_securityDisable MD2 in certificate chain validation
6863503javaclasses_securitySECURITY: MessageDigest.isEqual introduces timing attack vulnerabilities
6864911javaclasses_securityASN.1/DER input stream parser needs more work
6854303javaclasses_soundSun Java HsbParser.getSoundBank Stack Buffer Overflow Vulnerability
6657026javaclasses_swingNumerous static security flaws in Swing (findbugs)
6657138javaclasses_swingMutable statics in Windows PL&F (findbugs)
6824265javaclasses_util_i18n(tz) TimeZone.getTimeZone allows probing local filesystem
6632445javaimageioDoS from parsing BMPs with UNC ICC links
6862968javaimageioJPEG Image Writer quantization problem
6874643javaimageioImageI/O JPEG is vulnerable to Heap Overflow
6869694javainstalljava update malfunctioning
6869752java_deploymentdeployment_toolkitDeployment Toolkit plugin "launch" method vulnerable to exploits
6872824javawebstartgeneralarbitary code execution using java web start
6870531javawebstartotherREGRESSION:have problem to run JNLP app and applets with signed Jar files

Other bug fixes are listed in the following table.

BugIdCategorySubcategoryDescription
6842999hotspotruntime_systemUpdate hotspot windows os_win32 for windows 2008 R2
6804454javaclasses_2dRFE: Provide a way to control the printing dpi resolution from MSIE browser print. See also6801859
6813208javaclasses_awtpageDialog throws NPE from applet
6825342javaclasses_awtSecurity warning may change Z-order of top-level
6843003javaclasses_langWindows Server 2008 R2 system recognition
6860447javaclasses_securityAdd GlobalSign R3 Root certificate to the JDK
6872579javaclasses_securityAdd SECOM Root CA 2 to JDK
6880110javaclasses_util_i18n(tz) Support tzdata2009m
6814140javaclasses_util_loggingdeadlock due to synchronized demandLogger() code that locks ServerLogManager
6879614jaxpparsecom.sun.org.apache.xerces.internal.jaxp.DocumentBuilderImpl failing to parse xml document

[8]ページ先頭

©2009-2025 Movatter.jp