[ubuntu/groovy-proposed] openjdk-8 8u262-b10-0ubuntu1 (Accepted)

Tiago Stürmer Daitx tiago.daitx at ubuntu.com
Fri Jul 17 02:20:20 UTC 2020


openjdk-8 (8u262-b10-0ubuntu1) groovy; urgency=medium

  * Update to 8u262-b10 (GA). Update aarch32 to 8u262-b09 (no
    hotspot changes between b09 and b10).
  * Security fixes:
    - JDK-8028431, CVE-2020-14579: NullPointerException in
      DerValue.equals(DerValue)
    - JDK-8028591, CVE-2020-14578: NegativeArraySizeException in
      sun.security.util.DerInputStream.getUnalignedBitString()
    - JDK-8237117, CVE-2020-14556: Better ForkJoinPool behavior
    - JDK-8237592, CVE-2020-14577: Enhance certificate verification
    - JDK-8238002, CVE-2020-14581: Better matrix operations
    - JDK-8238920, CVE-2020-14583: Better Buffer support
    - JDK-8240119, CVE-2020-14593: Less Affine Transformations
    - JDK-8242136, CVE-2020-14621: Better XML namespace handling
    - JDK-8230613: Better ASCII conversions
    - JDK-8231800: Better listing of arrays
    - JDK-8232014: Expand DTD support
    - JDK-8233255: Better Swing Buttons
    - JDK-8234032: Improve basic calendar services
    - JDK-8234042: Better factory production of certificates
    - JDK-8234418: Better parsing with CertificateFactory
    - JDK-8234836: Improve serialization handling
    - JDK-8236191: Enhance OID processing
    - JDK-8238804: Enhance key handling process
    - JDK-8238842: AIOOBE in GIFImageReader.initializeStringTable
    - JDK-8238843: Enhanced font handing
    - JDK-8238925: Enhance WAV file playback
    - JDK-8240482: Improved WAV file playback
    - JDK-8241379: Update JCEKS support
    - JDK-8241522: Manifest improved jar headers redux
  * debian/patches/zero-x32.diff: remove SocketImpl.c hunks which
    have been applied upstream.
  * debian/patches/default-jvm-cfg-default.diff: fixed fuzz.
  * debian/patches/pass-extra-flags.diff: fixed fuzz.
  * debian/patches/system-lcms.diff: fixed fuzz.

Date: Wed, 24 Jun 2020 21:29:14 +0000
Changed-By: Tiago Stürmer Daitx <tiago.daitx at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/openjdk-8/8u262-b10-0ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 24 Jun 2020 21:29:14 +0000
Source: openjdk-8
Architecture: source
Version: 8u262-b10-0ubuntu1
Distribution: groovy
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Tiago Stürmer Daitx <tiago.daitx at ubuntu.com>
Changes:
 openjdk-8 (8u262-b10-0ubuntu1) groovy; urgency=medium
 .
   * Update to 8u262-b10 (GA). Update aarch32 to 8u262-b09 (no
     hotspot changes between b09 and b10).
   * Security fixes:
     - JDK-8028431, CVE-2020-14579: NullPointerException in
       DerValue.equals(DerValue)
     - JDK-8028591, CVE-2020-14578: NegativeArraySizeException in
       sun.security.util.DerInputStream.getUnalignedBitString()
     - JDK-8237117, CVE-2020-14556: Better ForkJoinPool behavior
     - JDK-8237592, CVE-2020-14577: Enhance certificate verification
     - JDK-8238002, CVE-2020-14581: Better matrix operations
     - JDK-8238920, CVE-2020-14583: Better Buffer support
     - JDK-8240119, CVE-2020-14593: Less Affine Transformations
     - JDK-8242136, CVE-2020-14621: Better XML namespace handling
     - JDK-8230613: Better ASCII conversions
     - JDK-8231800: Better listing of arrays
     - JDK-8232014: Expand DTD support
     - JDK-8233255: Better Swing Buttons
     - JDK-8234032: Improve basic calendar services
     - JDK-8234042: Better factory production of certificates
     - JDK-8234418: Better parsing with CertificateFactory
     - JDK-8234836: Improve serialization handling
     - JDK-8236191: Enhance OID processing
     - JDK-8238804: Enhance key handling process
     - JDK-8238842: AIOOBE in GIFImageReader.initializeStringTable
     - JDK-8238843: Enhanced font handing
     - JDK-8238925: Enhance WAV file playback
     - JDK-8240482: Improved WAV file playback
     - JDK-8241379: Update JCEKS support
     - JDK-8241522: Manifest improved jar headers redux
   * debian/patches/zero-x32.diff: remove SocketImpl.c hunks which
     have been applied upstream.
   * debian/patches/default-jvm-cfg-default.diff: fixed fuzz.
   * debian/patches/pass-extra-flags.diff: fixed fuzz.
   * debian/patches/system-lcms.diff: fixed fuzz.
Checksums-Sha1:
 6a1cb076204a80ef19b6147067b9f44a8eec3039 4790 openjdk-8_8u262-b10-0ubuntu1.dsc
 1837bc614285e208b09ec54664848729c209fe4d 72662968 openjdk-8_8u262-b10.orig.tar.xz
 9c0065f1e464bd2b4f9c92b3f0fb5248562769c7 245948 openjdk-8_8u262-b10-0ubuntu1.debian.tar.xz
 493ef66edf6b2bb127a73f6783c9549bb80dfd9d 19330 openjdk-8_8u262-b10-0ubuntu1_source.buildinfo
Checksums-Sha256:
 1169f95f1140ee06284601863f4198fbf728c1a1656dbe67ebd6a00545f30dc0 4790 openjdk-8_8u262-b10-0ubuntu1.dsc
 1d0170b259af48b0b0ddf4a224f8162253b29267d3a4847658b3f7ce813f13f1 72662968 openjdk-8_8u262-b10.orig.tar.xz
 ca12bd07a0bfa45c9c49b7de292b74338eeb6331bbc37380b0e85524ca3d3d5d 245948 openjdk-8_8u262-b10-0ubuntu1.debian.tar.xz
 9f10a39a969fee534dc9763e3d9f0674c8c1a6f5bf83890c5deec1c345ce1930 19330 openjdk-8_8u262-b10-0ubuntu1_source.buildinfo
Files:
 336448833025b77ca604b5b917517780 4790 java optional openjdk-8_8u262-b10-0ubuntu1.dsc
 67aae67143972fbebd97db6f8212c61c 72662968 java optional openjdk-8_8u262-b10.orig.tar.xz
 6001647ebd39cb3b8e9625b914e55a67 245948 java optional openjdk-8_8u262-b10-0ubuntu1.debian.tar.xz
 62c8bcb36bfcc7759544dea86b15c712 19330 java optional openjdk-8_8u262-b10-0ubuntu1_source.buildinfo
Original-Maintainer: OpenJDK Team <openjdk at lists.launchpad.net>

-----BEGIN PGP SIGNATURE-----

iQJLBAEBCgA1FiEE+JEitvb+Hru9UiZmnDJEJjvUHeAFAl8RBsIXHHRpYWdvLmRh
aXR4QHVidW50dS5jb20ACgkQnDJEJjvUHeDdJQ/+IDY9Hvt/y+k3x8NzPoqk1bY7
WahqISHlj96jMN97zMWzb02jAx1XIIg3LpDj5WSQMXEG+zVl1JV9iFmgu3IBLw5p
1dewwkzIwaM2McqWbaQktrOIzvUCIVP+VO65pltSB9wsqqu54TBKAbcpWhMTBg7U
/sZj4cDFWpsbASGM+Y8vzRzgF4jPhHNFbuTnjilbPdcet498JcOBxO9v0e4SYB1v
+c3L45hkff5UUnl1dyhpFLUjNXbUeww45jGV2lqPLNi041ZegBEKRpen1uHh8L4K
4Wegj9yJcmhbnopSzqwqnsYhjdfq9dGhVW3iDoAyUvd9ANuNR4psL9ROV6BQywQn
wr3QFRWWMbKH8iWp5coMWdHUUmtA5HxkguXltu2i4XG8RQL9eWn0zyKtkghk6+9u
dM7sg8pz7idYbE6Ggqfx1k3ILQoMNdLSGqgwHMdP1myK/wRcpnQTyl5LTABlPYF1
iOeAIXGMEKwPMeGKa4dMR3NFUhFSuKajN0S+RQ6p9q8an9+kmEVHkRVdUqXf5Srn
I5Bgabpor4w9rubQhB70ZpLoU0HT9NzBXxpAy3ATSipSxN9IpvS7JURkjsVzjXN8
lZD0BREHPUkA9KBo4nTgFttOiflX32CjmkU2cxsRI8H81uPZgPCTPDvOSKDYgG00
A/kqWTJQTiV0LC28Xdk=
=63I6
-----END PGP SIGNATURE-----


More information about the Groovy-changes mailing list