changeset 3207:32d0b5a27dc2

Add CVE numbers to security issues for 1.13.7. 2015-04-15 Andrew John Hughes <gnu.andrew@redhat.com> * NEWS: Add CVE numbers.
author Andrew John Hughes <gnu.andrew@redhat.com>
date Wed, 15 Apr 2015 01:06:13 +0100
parents ac0650bb1c81
children 69d82d8f85f9
files ChangeLog NEWS
diffstat 2 files changed, 10 insertions(+), 6 deletions(-) [+]
line wrap: on
line diff
--- a/ChangeLog	Fri Apr 10 18:24:49 2015 +0100
+++ b/ChangeLog	Wed Apr 15 01:06:13 2015 +0100
@@ -1,3 +1,7 @@
+2015-04-15  Andrew John Hughes  <gnu.andrew@redhat.com>
+
+	* NEWS: Add CVE numbers.
+
 2015-04-10  Andrew John Hughes  <gnu.andrew@redhat.com>
 
 	PR2294: Auto-generated jconsole.desktop
--- a/NEWS	Fri Apr 10 18:24:49 2015 +0100
+++ b/NEWS	Wed Apr 15 01:06:13 2015 +0100
@@ -17,19 +17,19 @@
 * Security fixes
   - S8059064: Better G1 log caching
   - S8060461: Fix for JDK-8042609 uncovers additional issue
-  - S8064601: Improve jar file handling
+  - S8064601, CVE-2015-0480: Improve jar file handling
   - S8065286: Fewer subtable substitutions
   - S8065291: Improved font lookups
   - S8066479: Better certificate chain validation
   - S8067050: Better font consistency checking
   - S8067684: Better font substitutions
-  - S8067699: Better glyph storage
-  - S8068320: Limit applet requests
-  - S8068720: Better certificate options checking
+  - S8067699, CVE-2015-0469: Better glyph storage
+  - S8068320, CVE-2015-0477: Limit applet requests
+  - S8068720, CVE-2015-0488: Better certificate options checking
   - S8069198: Upgrade image library
-  - S8071726: Better RSA optimizations
+  - S8071726, CVE-2015-0478: Better RSA optimizations
   - S8071818: Better vectorization on SPARC
-  - S8071931: Return of the phantom menace
+  - S8071931, CVE-2015-0460: Return of the phantom menace
 * Import of OpenJDK6 b35
   - OJ55: Synchronise whitespace in TimeZoneNames files with OpenJDK 7 versions.
   - OJ56: Update 3rd party readme and license for LibPNG v 1.6.16