-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 06 Sep 2012 15:15:52 +0200 Source: icedtea-web Binary: icedtea-netx icedtea6-plugin icedtea-plugin icedtea-netx-common icedtea-6-plugin icedtea-7-plugin Architecture: source amd64 all Version: 1.3-1 Distribution: unstable Urgency: high Maintainer: OpenJDK Team <openjdk@lists.launchpad.net> Changed-By: Matthias Klose <doko@ubuntu.com> Description: icedtea-6-plugin - web browser plugin based on OpenJDK and IcedTea to execute Java a icedtea-7-plugin - web browser plugin based on OpenJDK and IcedTea to execute Java a icedtea-netx - NetX - implementation of the Java Network Launching Protocol (JNL icedtea-netx-common - NetX - implementation of the Java Network Launching Protocol (JNL icedtea-plugin - web browser plugin to execute Java applets (dependency package) icedtea6-plugin - web browser plugin to execute Java applets (dependency package) Closes: 681269 Changes: icedtea-web (1.3-1) unstable; urgency=high . * IcedTea-Web 1.3 release. * Security updates: - CVE-2012-3422: Potential read from an uninitialized memory location. - CVE-2012-3423: Incorrect handling of not 0-terminated strings. * NetX fixes: - PR898: signed applications with big jnlp-file doesn't start (webstart affect like "frozen"). - PR811: javaws is not handling urls with spaces (and other characters needing encoding) correctly. * Plugin fixes: - PR820: IcedTea-Web 1.1.3 crashing Firefox when loading Citrix XenApp. - PR863: Error passing strings to applet methods in Chromium. - PR895: IcedTea-Web searches for missing classes on each loadClass or findClass. - PR861: Allow loading from non codebase hosts. Allow code to connect to hosting server. - PR518: NPString.utf8characters not guaranteed to be nul-terminated. - PR722: META-INF/ unsigned entries should be ignored in signing. - PR855: AppletStub getDocumentBase() doesn't return full URL. - PR1011: Folders treated as jar files in archive tag. - PR1106: Buffer overflow in plugin table. - PR975: Plugin should not include classpaths specified in jar manifests when using jnlp_href. - PR588: Cookies not written from cookie jar to browser cookies. * Common fixes: - PR918: java applet windows uses a low resulution black/white icon. - Disambiguate signed applet security prompt from certificate warning. - PR955: regression: SweetHome3D fails to run. . * For Ubuntu quantal, set priorities for alternatives higher than for OpenJDK 6. * Call update-alternatives when the existing priority for the alternative is lower than the current one. * icedtea-netx: Don't set the alternatives to a OpenJDK which is not installed. Closes: #681269. * Allow building the plugin for OpenJDK 6 using OpenJDK 7. * Build with hardening defaults. Checksums-Sha1: c4378ba537e362f50002221e87b75fb33aa9edaa 1722 icedtea-web_1.3-1.dsc 348f5484daf06edeaa615ecf3045d4ce85c81452 987785 icedtea-web_1.3.orig.tar.gz 32d1d495ce5eaa36a0667bc910f8605e30e76427 16662 icedtea-web_1.3-1.debian.tar.gz 7f7e116ca0730222afe9ac7758ab33fc15732ece 18430 icedtea-netx_1.3-1_amd64.deb 4223644c62e8856eeaad498131bf3f521d2d60e7 90224 icedtea-6-plugin_1.3-1_amd64.deb 5efb392133a1c4c8eb858607241004a612c83efd 90172 icedtea-7-plugin_1.3-1_amd64.deb b8318cbc25e3d88feb41052d5dc54cb3c6aa3a6f 882 icedtea6-plugin_6b21.3-1_all.deb 3532fa43c0ebae93986567dc683fe8af1ce585fc 625984 icedtea-netx-common_1.3-1_all.deb a521614ed7b89175ea51918caa44d307a8829e1c 7636 icedtea-plugin_1.3-1_all.deb Checksums-Sha256: 587595971b5de7fdd40086c2930d432a1e603c259fe72e47cfe51236abd21b7d 1722 icedtea-web_1.3-1.dsc d46ec10700732cea103da2aae64ff01e717cb1281b83e1797ce48cc53280b49f 987785 icedtea-web_1.3.orig.tar.gz db95aafe48ac4e90d688b0136e4bc47d2aa31668b617b638c00c217df758068c 16662 icedtea-web_1.3-1.debian.tar.gz 97182e163635cbfe5ad93509304df882575d9c0091c6b7f91519bceab2bab22c 18430 icedtea-netx_1.3-1_amd64.deb f30756a1b1519c60b6e5289db5daec26c4479567adb812fffa609ad7c05d81af 90224 icedtea-6-plugin_1.3-1_amd64.deb da963caea6bd6e9ee6265699766c9a01162af4b3a22149211968374e0a5b6f46 90172 icedtea-7-plugin_1.3-1_amd64.deb 23aac8a808c8b18383702dece373ae2737b255884e30575be4e2a78347c2a157 882 icedtea6-plugin_6b21.3-1_all.deb c3a596034b4dcad1fcc1c30112e3ede11bcba1e1568e83be97d6358f64798eed 625984 icedtea-netx-common_1.3-1_all.deb 9dc2a692d9e73a18226799c7953121285409ec70ddedeaee2f357ec9f93fdb53 7636 icedtea-plugin_1.3-1_all.deb Files: 5782672d22574c433401b23c529593f5 1722 java extra icedtea-web_1.3-1.dsc a19661c0b31725fbf0e5e31303ac74fa 987785 java extra icedtea-web_1.3.orig.tar.gz d908de8bf1699fa4330725b155180ba5 16662 java extra icedtea-web_1.3-1.debian.tar.gz 1de217cd9606b53100d26a38ec28b811 18430 java extra icedtea-netx_1.3-1_amd64.deb b76aaf509d0c8fc800d89ea88a63828d 90224 web extra icedtea-6-plugin_1.3-1_amd64.deb 65c0979ec33704ff94efbe0ef5abd530 90172 web extra icedtea-7-plugin_1.3-1_amd64.deb 691c92c8ba309192b832f081d5db2154 882 web extra icedtea6-plugin_6b21.3-1_all.deb e84aed2efbf5ba7f8f0ffe535bf3453d 625984 java extra icedtea-netx-common_1.3-1_all.deb 0ae5b03205f88ff6d6100f52e6033ec4 7636 web extra icedtea-plugin_1.3-1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAlBIrK8ACgkQStlRaw+TLJyRJQCgk2GyyUtnrV/bWq75DNKR2Iiy CGYAnij/7rD89mIIH5y3px+gooTjsysF =zipz -----END PGP SIGNATURE-----