Package: release.debian.org Severity: normal Tags: jessie User: release.debian....@packages.debian.org Usertags: pu
Hi, I'd like to update icedtea-web in jessie to 1.5.3 in the next jessie point release. This fixes two security issues (CVE-2015-5234, CVE-2015-5235), which are not easily backportable, so I rather made the update to the minor point update which fixes those (similar to what we do with openjdk-7 itself). I've tested this on a jessie with various web applets I could find (fortunately finding these in the wild is becoming increasingly difficult!). The debdiff is here: https://people.debian.org/~jmm/icedtea-web.debdiff (the actual change to the debian/ directory is just the changelog entry bump). Ubuntu has also updated to those point bugfix updates in USNs for a while now. Cheers, Moritz