Movatterモバイル変換


[0]ホーム

URL:


Country
Contact Sales

Update Release Notes

Changes in 1.6.0_15 (6u15)

The full internal version number for this update release is 1.6.0_15-b03 (where "b" means "build"). The external version number is 6u15.

OlsonData 2009i

6u15 contains Olson time zone data version 2009i. For more information, refer toTimezone Data Versions in the JRE Software .

Security Baseline

6u15 specifies the following security baselines for use with Java Plug-in technology:

JRE Family VersionJava SESecurity BaselineJava SE for BusinessSecurity Baseline
5.01.5.0_201.5.0_20
1.4.21.4.2_191.4.2_22

For more information about the security baseline, seeDeploying Java Applets With Family JRE Versions in Java Plug-in for Internet Explorer .

Root Certificates

Root Certificates are included in this release.

  • Added one new root certificate and removed 3 root certificates from Entrust. (Refer to6805338.)
  • Added three new root certificates from Keynectis. (Refer to6845457.)
  • Added three new root certificates from Quovadis. (Refer to6846473.)

Blacklist Entries

This update release includes the following new entry to the Blacklist:

  • JNLPAppletLauncher
  • Note: Users should install JDK and JRE 6 Update 15 or later on systems running JDK and JRE 5.0 and SDK and JRE 1.4.2 to take advantage of this blacklist feature. For more information see theBlacklist Jar Feature section in the 6u14 Release Notes.

Debug Issue

Java ™ Virtual Machine Tool Interface (JVM TI) breakpoints are reliable only when either the Parallel Scavenge garbage collector (-XX:+UseParallelGC) or the Parallel Compacting garbage collector (-XX:+UseParallelOldGC) is used.

When other collectors are used, breakpoints may stop functioning, and JVM TI object tags may become unusable after a full GC operation is performed. Java ™ Debug Interface (JDI) ThreadReferences have an embedded thread ID that depends on JVM TI object tags, thus the embedded thread ID may change unexpectedly. This may cause confusion in thread based JDI events.

Note that the Serial garbage collector (-XX:+UseSerialGC) is vulnerable to this problem and is selected by default on some platforms. The work around is to explicitly select the Parallel Scavenge collector using the command line option-XX:+UseParallelGC.

(Refer to6862295.)

Bug Fixes

This release contains fixes for one or more security vulnerabilities.

Bug fixes for vulnerabilities are listed in the following table.

BugIdCategorySubcategoryDescription
6656610javaaccessibilityAccessibleResourceBundle.getContents exposes mutable static (findbugs)
6656586javaclasses_awtCursor.predefined is protected static mutable (findbugs)
6805231javaclasses_awtSecurity Warning Icon is missing in Windows 2000 Prof from Jdk build 6u12
6818787javaclasses_awtIt is possible to reposition the security icon too far from the border of the window on X11
6823373javaclasses_awt[ZDI-CAN-460] Java Web Start JPEG header parsing needs more scruity
6660539javaclasses_beansIntrospector cache mutable static
6777487javaclasses_beansEncoder allows reading private variables with certain names
6801071javaclasses_netRemote sites can compromise user privacy and possibly hijack web session
6801497javaclasses_netProxy is assumed to be immutable but is non-final
6657695javaclasses_securityAbstractSaslImpl.logger is a static mutable (findbugs)
6824440javaclasses_securityXML Signature HMAC issue
6657625javaclasses_soundRmfFileReader/StandardMidiFileWriter.types are public mutable statics (findbugs)
6738524javaclasses_soundJDK13Services allows read access to system properties from untrusted code
6777448javaclasses_soundJDK13Services.getProviders creates instances with full privileges
6588003javaclasses_swingLayoutQueue mutable statics
6660049javaclasses_swingSynth Region.uiToRegionMap/lowerCaseNameMap are mutable statics
6849518javaclasses_swingNPE is thrown in jemmy library since 6u15 b01 at javax.swing.plaf.synth.SynthContext.isSubregion()
6656625javaimageioImageReaderSpi.STANDARD_INPUT_TYPE/ImageWriterSpi.STANDARD_OUTPUT_TYPE are mutable static (findbugs)
6657133javaimageioMutable statics in imageio plugins (findbugs)
6830335javajarJava JAR Pack200 Decompression Integer Overflow Vulnerability
6755840java_pluginpluginVersion selection allows old zip and certificate handling to be exploited
6848964javawebstartgeneralTCK jnlp test jnlp_file/appletDesc/index.html#misc fails with NPE starting 6u15 b01
6862844javawebstartotherjava web start ActiveX control security problem caused by ATL PROP_ENTRY macro
6845701jaxpparseXerces2 Java XML library infinite loop with malformed XML input
6813167jax-wsother6u14 JAX-WS audit mutable static bugs
6736293jmxclassesOpenType checks can be bypassed through finalizer resurrection
6657619jndidnsDnsContext.debug is public static mutable (findbugs)

Other bug fixes are listed in the following table.

BugIdCategorySubcategoryDescription
6786503hotspotgarbage_collectorOverflow list performance can be improved
6787254hotspotgarbage_collectorWork queue capacity can be increased substantially on some platforms
6805338javaclasses_securityAdd 1 new Entrust root CA cert and remove 3 others with 1024 bit keys
6845457javaclasses_securityAdd root certs for Keynectis CA
6846473javaclasses_securityAdd QuoVadis root CA certs to the JRE
6848984javaclasses_util_i18n(tz) Support tzdata2009i
6851214javaclasses_util_i18n(tz) New Jordan rule creates a failure for SimpleTimeZone parsing post tzdata2009h
6845077javainstallsilent JDK should install JRE/Java DB silently
6846531javawebstartotherREGRESSION application from ocie.net does not work with 6.0_14
6461727jcepkcs11_cspTripleDES KeyGenerators in SunPKCS11 and SunJCE do not agree on key length

[8]ページ先頭

©2009-2025 Movatter.jp