Your message dated Sat, 9 May 2015 13:17:51 +0200
with message-id <[email protected]>
and subject line Re: Bug#778511: icu: possibly more to CVE-2014-6585
has caused the Debian Bug report #778511,
regarding icu: possibly more to CVE-2014-6585
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
778511: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=778511
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
package: src:icu
version: 52.1-7
severity: important
tags: security
openjdk's changes for CVE-2014-6585 [0] add some additional checking
for the pointers in source/layout/ContextualSubstSubtables.cpp that
have yet to be included in upstream icu.
Also see even more checks added to embedded icu in the latest openjdk-8 package:
jdk-jdk8u40-b22/src/share/native/sun/font/layout/ContextualSubstSubtables.cpp
These are possibly the currently private changes hinted at in upstream
bug #11422:
http://bugs.icu-project.org/trac/ticket/11422
Best wishes,
Mike
[0] https://bugzilla.redhat.com/attachment.cgi?id=981489
--- End Message ---
--- Begin Message ---
Source: icu
Source-Version: 55.1-1
On dom, feb 15, 2015 at 09:32:53 -0500, Michael Gilbert wrote:
> package: src:icu
> version: 52.1-7
> severity: important
> tags: security
>
> openjdk's changes for CVE-2014-6585 [0] add some additional checking
> for the pointers in source/layout/ContextualSubstSubtables.cpp that
> have yet to be included in upstream icu.
>
> Also see even more checks added to embedded icu in the latest openjdk-8
> package:
> jdk-jdk8u40-b22/src/share/native/sun/font/layout/ContextualSubstSubtables.cpp
>
> These are possibly the currently private changes hinted at in upstream
> bug #11422:
> http://bugs.icu-project.org/trac/ticket/11422
It seems these changes have now been merged upstream (along with other ones) in
http://bugs.icu-project.org/trac/changeset/37086 and uploaded to experimental.
Closing this bug now.
Cheers
signature.asc
Description: Digital signature
--- End Message ---