Hello. :) https://bugzilla.redhat.com/show_bug.cgi?id=1465573#c24 says it affects all 5.x version. But Debian haven't shipped this version yet. And upstream patched files doesn't exist in 4.3.3 (version in Debian sid). So could you please elaborate on how your research find 4.3.3 affected ?
-- Abhijith __ This is the maintainer address of Debian's Java team <http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers>. Please use debian-j...@lists.debian.org for discussions and questions.