* IcedTea7 2.5.4 release (based on OpenJDK 7u75).
* Security fixes
- S8046656: Update protocol support.
- S8047125, CVE-2015-0395: (ref) More phantom object references.
- S8047130: Fewer escapes from escape analysis.
- S8048035, CVE-2015-0400: Ensure proper proxy protocols.
- S8049253: Better GC validation.
- S8050807, CVE-2015-0383: Better performing performance data handling.
- S8054367, CVE-2015-0412: More references for endpoints.
- S8055304, CVE-2015-0407: More boxing for DirectoryComboBoxModel.
- S8055309, CVE-2015-0408: RMI needs better transportation considerations.
- S8055479: TLAB stability.
- S8055489, CVE-2014-6585: Better substitution formats.
- S8056264, CVE-2014-6587: Multicast support improvements.
- S8056276, CVE-2014-6591: Fontmanager feature improvements.
- S8057555, CVE-2014-6593: Less cryptic cipher suite management.
- S8058982, CVE-2014-6601: Better verification of an exceptional invokespecial.
- S8059485, CVE-2015-0410: Resolve parsing ambiguity.
- S8061210, CVE-2014-3566: Issues in TLS.
openjdk-7 (7u71-2.5.3-2) unstable; urgency=medium
* Regenerate the .orig.tar to omit a third hotspot tarball.
* Really fix the libjpeg runtime dependency for sid and jessie.
Closes: #766601.
* Fix regression running JamVM after the 2.5.3 security update.
Closes: #767771. LP: #1382205.
* Fix regression running CACAO after the 2.5.3 security update.
* Backport S8000897, VM crash in CompileBroker. Closes: #768747.
* Fix building icedtea-sound on x32 (patch dropped in 7u71-2.5.3-1).
Closes: #766610.
* Don't use the compatibility path names from the ttf-dejavu packages
for recent releases. LP: #1362099.
-- Jamie Strandboge <email address hidden> Mon, 26 Jan 2015 17:35:46 -0600
This bug was fixed in the package openjdk-7 - 7u75-2. 5.4-1~utopic1
--------------- 5.4-1~utopic1) utopic-security; urgency=medium
openjdk-7 (7u75-2.
* Backport to utopic
openjdk-7 (7u75-2.5.4-1) unstable; urgency=high
* IcedTea7 2.5.4 release (based on OpenJDK 7u75). oxModel.
* Security fixes
- S8046656: Update protocol support.
- S8047125, CVE-2015-0395: (ref) More phantom object references.
- S8047130: Fewer escapes from escape analysis.
- S8048035, CVE-2015-0400: Ensure proper proxy protocols.
- S8049253: Better GC validation.
- S8050807, CVE-2015-0383: Better performing performance data handling.
- S8054367, CVE-2015-0412: More references for endpoints.
- S8055304, CVE-2015-0407: More boxing for DirectoryComboB
- S8055309, CVE-2015-0408: RMI needs better transportation considerations.
- S8055479: TLAB stability.
- S8055489, CVE-2014-6585: Better substitution formats.
- S8056264, CVE-2014-6587: Multicast support improvements.
- S8056276, CVE-2014-6591: Fontmanager feature improvements.
- S8057555, CVE-2014-6593: Less cryptic cipher suite management.
- S8058982, CVE-2014-6601: Better verification of an exceptional invokespecial.
- S8059485, CVE-2015-0410: Resolve parsing ambiguity.
- S8061210, CVE-2014-3566: Issues in TLS.
openjdk-7 (7u71-2.5.3-2) unstable; urgency=medium
* Regenerate the .orig.tar to omit a third hotspot tarball.
* Really fix the libjpeg runtime dependency for sid and jessie.
Closes: #766601.
* Fix regression running JamVM after the 2.5.3 security update.
Closes: #767771. LP: #1382205.
* Fix regression running CACAO after the 2.5.3 security update.
* Backport S8000897, VM crash in CompileBroker. Closes: #768747.
* Fix building icedtea-sound on x32 (patch dropped in 7u71-2.5.3-1).
Closes: #766610.
* Don't use the compatibility path names from the ttf-dejavu packages
for recent releases. LP: #1362099.
-- Jamie Strandboge <email address hidden> Mon, 26 Jan 2015 17:35:46 -0600