[Openjdk] [Bug 1933832] Re: Path traversal leads to arbitrary file read

2021-09-23 Thread Marc Deslauriers
** Changed in: openjdk-13 (Ubuntu) Status: New => Won't Fix ** Changed in: openjdk-14 (Ubuntu) Status: New => Won't Fix ** Changed in: openjdk-15 (Ubuntu) Status: New => Won't Fix ** Changed in: openjdk-16 (Ubuntu) Status: New => Won't Fix ** Changed in: openjdk-17

[Openjdk] [Bug 1933832] Re: Path traversal leads to arbitrary file read

2021-09-16 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-8 in Ubuntu. https://bugs.launchpad.net/bugs/1933832 Title: Path traversal leads to arbitrary file read Status in

[Openjdk] [Bug 1916327] Re: package openjdk-8-jre-headless 8u282-b08-0ubuntu1~20.04 failed to install/upgrade: Versuch, gemeinsam benutztes »/etc/java-8-openjdk/security/java.security« zu überschreibe

2021-03-09 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 828756] Re: getting "connection is untrusted" warnings

2018-12-03 Thread Marc Deslauriers
This is an ancient bug and likely no longer applies to recent releases. As such, I am closing it. If anyone is still hitting this issue with current releases, please file a new bug. ** Changed in: ca-certificates-java (Ubuntu) Status: Confirmed => Invalid ** Changed in: empathy (Ubuntu)

[Openjdk] [Bug 1707082] Re: regression on openjdk-8 caused by the S8169392 security update

2017-07-28 Thread Marc Deslauriers
** Changed in: openjdk-8 (Ubuntu) Importance: Undecided => Critical -- You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-8 in Ubuntu. https://bugs.launchpad.net/bugs/1707082 Title: regression on openjdk-8 caused by the S8169392 security

[Openjdk] [Bug 1564780] Re: package openjdk-7-jre-headless 7u95-2.6.4-0ubuntu0.14.04.1 failed to install/upgrade: cannot copy extracted data for './usr/lib/jvm/java-7-openjdk-amd64/jre/lib/rt.jar' to

2016-04-08 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 1509708] Re: package openjdk-7-jre 7u79-2.5.6-0ubuntu1.14.04.1 [modified: usr/share/applications/openjdk-7-policytool.desktop] failed to install/upgrade: trying to overwrite shared '/us

2015-10-29 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 1438575] Re: OpenJdk 7 and OpenJdk 8 miss-report the os.arch field and cause java apps to crash.

2015-09-15 Thread Marc Deslauriers
Looks like openjdk-7 in wily now includes this. Marking as fix released. ** Changed in: openjdk-7 (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-7 in Ubuntu.

[Openjdk] [Bug 1448548] Re: OpenJDK 7/8 don't generate .desktop needed by nautilus

2015-08-13 Thread Marc Deslauriers
cautious-launcher is an Ubuntu-specific helper that ensures .jar files have the required executable bit set in order to comply with the following: https://wiki.ubuntu.com/SecurityTeam/Policies#Execute- Permission_Bit_Required The problem with openjdk is with this section in the rules file: #

[Openjdk] [Bug 1448548] Re: OpenJDK 7/8 don't generate .desktop needed by nautilus

2015-08-13 Thread Marc Deslauriers
Actually, I've read that wrong. I think the issue is the comparison here: ifeq ($(java_launcher),cautious-launcher) -- You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-7 in Ubuntu. https://bugs.launchpad.net/bugs/1448548 Title: OpenJDK

[Openjdk] [Bug 1449652] Re: jks-keystore doesn't work for all Java versions

2015-04-28 Thread Marc Deslauriers
** Also affects: ca-certificates-java (Ubuntu Vivid) Importance: Undecided Status: New ** Also affects: ca-certificates-java (Ubuntu Utopic) Importance: Undecided Status: New -- You received this bug notification because you are a member of OpenJDK, which is subscribed to

[Openjdk] [Bug 1258286] Re: CAcert should not be trusted by default

2014-04-02 Thread Marc Deslauriers
** Changed in: nss (Ubuntu Lucid) Status: New = Invalid ** Changed in: ca-certificates-java (Ubuntu Precise) Status: New = Invalid ** Changed in: ca-certificates-java (Ubuntu Lucid) Status: New = Invalid -- You received this bug notification because you are a member of

[Openjdk] [Bug 1283828] Re: Cannot find any provider supporting RSA/ECB/OAEPPadding error after upgrading to openjdk-6 6b27-1.12.6-1ubuntu0.12.04.4

2014-02-24 Thread Marc Deslauriers
** Changed in: openjdk-6 (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-6 in Ubuntu. https://bugs.launchpad.net/bugs/1283828 Title: Cannot find any provider

[Openjdk] [Bug 1224723] Re: Clamscan finds CVE-2013-2465 in openjdk-6-jre-headless

2013-09-30 Thread Marc Deslauriers
Thanks for reporting this. It looks like a false positive. None of the files are detected as being a virus once the archive is extracted, and online scanner don't detect the file as a virus. I've updated the list of known false positives here:

[Openjdk] [Bug 1224723] Re: Clamscan finds CVE-2013-2465 in openjdk-6-jre-headless

2013-09-30 Thread Marc Deslauriers
The Java.Exploit.CVE_2013_2465 virus takes advantage of unpatched versions of Java and OpenJDK which are vulnerable to CVE-2013-2465. The signature isn't meant to detect the vulnerability itself, but a specific piece of malware that targets it. OpenJDK got updated for this CVE in July:

[Openjdk] [Bug 1224723] Re: Clamscan finds CVE-2013-2465 in openjdk-6-jre-headless

2013-09-30 Thread Marc Deslauriers
I've submitted the false positive to ClamAV. -- You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-6 in Ubuntu. https://bugs.launchpad.net/bugs/1224723 Title: Clamscan finds CVE-2013-2465 in openjdk-6-jre-headless Status in “clamav” package

[Openjdk] [Bug 969075] Re: package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-03-30 Thread Marc Deslauriers
*** This bug is a duplicate of bug 967961 *** https://bugs.launchpad.net/bugs/967961 ** This bug has been marked a duplicate of bug 967961 package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error

[Openjdk] [Bug 968138] Re: package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-03-29 Thread Marc Deslauriers
*** This bug is a duplicate of bug 967961 *** https://bugs.launchpad.net/bugs/967961 ** This bug has been marked a duplicate of bug 967961 package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error

[Openjdk] [Bug 968123] Re: package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-03-29 Thread Marc Deslauriers
*** This bug is a duplicate of bug 967961 *** https://bugs.launchpad.net/bugs/967961 ** This bug has been marked a duplicate of bug 967961 package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error

[Openjdk] [Bug 968042] Re: package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-03-29 Thread Marc Deslauriers
*** This bug is a duplicate of bug 967961 *** https://bugs.launchpad.net/bugs/967961 ** This bug has been marked a duplicate of bug 967961 package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error

[Openjdk] [Bug 967961] Re: package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-03-29 Thread Marc Deslauriers
-java (Ubuntu Oneiric) Assignee: (unassigned) = Marc Deslauriers (mdeslaur) ** Changed in: ca-certificates-java (Ubuntu Oneiric) Importance: Undecided = High -- You received this bug notification because you are a member of OpenJDK, which is subscribed to ca-certificates-java in Ubuntu

[Openjdk] [Bug 968430] Re: package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-03-29 Thread Marc Deslauriers
*** This bug is a duplicate of bug 967961 *** https://bugs.launchpad.net/bugs/967961 ** This bug has been marked a duplicate of bug 967961 package ca-certificates-java 20110912ubuntu3.1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error

[Openjdk] [Bug 962378] Re: multiarch broke circular dependency workaround

2012-03-23 Thread Marc Deslauriers
** Summary changed: - ca-certificates-java tries to call java binary before it's installed + multiarch broke circular dependency workaround ** Changed in: ca-certificates-java (Ubuntu) Milestone: None = ubuntu-12.04-beta-2 ** Changed in: ca-certificates-java (Ubuntu) Assignee:

[Openjdk] [Bug 962378] Re: multiarch broke circular dependency workaround

2012-03-23 Thread Marc Deslauriers
** Changed in: ca-certificates-java (Ubuntu) Assignee: Canonical Foundations Team (canonical-foundations) = Marc Deslauriers (mdeslaur) -- You received this bug notification because you are a member of OpenJDK, which is subscribed to ca-certificates-java in Ubuntu. https

[Openjdk] [Bug 920758] Re: DigiNotar Root CA still present in ca-certificates-java

2012-03-22 Thread Marc Deslauriers
** Also affects: ca-certificates-java (Ubuntu Natty) Importance: Undecided Status: New ** Also affects: ca-certificates-java (Ubuntu Precise) Importance: Undecided Assignee: Marc Deslauriers (mdeslaur) Status: New ** Changed in: ca-certificates-java (Ubuntu Lucid

[Openjdk] [Bug 962378] Re: ca-certificates-java tries to call java binary before it's installed

2012-03-22 Thread Marc Deslauriers
-- You received this bug notification because you are a member of OpenJDK, which is subscribed to ca-certificates-java in Ubuntu. https://bugs.launchpad.net/bugs/962378 Title: ca-certificates-java tries to call java binary before it's installed Status in “ca-certificates-java” package in

[Openjdk] [Bug 962378] [NEW] ca-certificates-java tries to call java binary before it's installed

2012-03-22 Thread Marc Deslauriers
Public bug reported: The postinst tries to call java without it being available... root@sec-precise-amd64:/etc# apt-get install ca-certificates-java Reading package lists... Done Building dependency tree Reading state information... Done The following packages were automatically

[Openjdk] [Bug 962381] [NEW] apport hook crashes because of lack of appropriate privileges

2012-03-22 Thread Marc Deslauriers
Public bug reported: Apport hook crashes because of lack of appropriate privileges: mdeslaur@sec-precise-amd64:~$ ubuntu-bug ca-certificates-java ERROR: hook /usr/share/apport/general-hooks/ubuntu.py crashed: Traceback (most recent call last): File

[Openjdk] [Bug 962381] Re: apport hook crashes because of lack of appropriate privileges

2012-03-22 Thread Marc Deslauriers
** Package changed: ca-certificates-java (Ubuntu) = apport (Ubuntu) -- You received this bug notification because you are a member of OpenJDK, which is subscribed to ca-certificates-java in Ubuntu. https://bugs.launchpad.net/bugs/962381 Title: apport hook crashes because of lack of

[Openjdk] [Bug 962378] Re: ca-certificates-java tries to call java binary before it's installed

2012-03-22 Thread Marc Deslauriers
ca-certificates-java and openjdk-6-jre-headless have circular dependencies -- You received this bug notification because you are a member of OpenJDK, which is subscribed to ca-certificates-java in Ubuntu. https://bugs.launchpad.net/bugs/962378 Title: ca-certificates-java tries to call java

[Openjdk] [Bug 962378] Re: ca-certificates-java tries to call java binary before it's installed

2012-03-22 Thread Marc Deslauriers
The ca-certificates-java postinst tries to work around the circular dependency with the following: setup_path() { for jvm in java-6-openjdk java-7-openjdk java-6-sun; do if [ -x /usr/lib/jvm/$jvm/bin/java ]; then break fi done export

[Openjdk] [Bug 920758] Re: DigiNotar Root CA still present in ca-certificates-java

2012-03-19 Thread Marc Deslauriers
Argh, stupid copy paste...reposting info to get readable layout: First bug: natty and earlier's ca-certificates-java hook doesn't strip the right filename extension, so the DigiNotar cert doesn't get removed from the java store when ca-certificates is upgraded. Second bug: oneiric and later's

[Openjdk] [Bug 920758] Re: DigiNotar Root CA still present in ca-certificates-java

2012-03-19 Thread Marc Deslauriers
Testing has revealed a whole slew of issues with the way the debian packaging attemps to update the java cert store: bug #1: natty and earlier's ca-certificates-java hook doesn't strip the right filename extension, so the DigiNotar cert doesn't get removed from the java store when

[Openjdk] [Bug 927423] Re: jre/lib/security/cacerts symlink is broken

2012-02-06 Thread Marc Deslauriers
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability ** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of OpenJDK, which is subscribed to

[Openjdk] [Bug 816453] Re: package openjdk-6-jre-headless 6b22-1.10.2-0ubuntu1~11.04.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 2

2011-08-01 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 816552] Re: Sweet Home3D 3.2 application crashed!

2011-08-01 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 805019] Re: package ca-certificates-java 20100412 failed to install/upgrade: Unterprozess installiertes post-installation-Skript gab den Fehlerwert 1 zurück

2011-07-06 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 760023] Re: package openjdk-6-jre-headless 6b20-1.9.7-0ubuntu1~10.04.1 failed to install/upgrade: il sottoprocesso vecchio script di post-installation ha restituito lo stato di errore 2

2011-04-19 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 763215] Re: Can't run Minecraft

2011-04-19 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 748430] Re: java crashed with SIGABRT in __kernel_vsyscall()

2011-04-08 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 744149] Re: JVM crashes after some time of running the system. Using JbossDrools , ehcache

2011-03-28 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 689491] Re: package openjdk-6-jre-headless 6b20-1.9.2-0ubuntu1~10.04.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 2

2010-12-14 Thread Marc Deslauriers
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a regular (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Openjdk] [Bug 359407] Re: Jaunty icedtea6-plugin doesn’t work in Firefox 3.5

2010-08-12 Thread Marc Deslauriers
** CVE removed: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2009-3555 -- Jaunty icedtea6-plugin doesn’t work in Firefox 3.5 https://bugs.launchpad.net/bugs/359407 You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-6 in ubuntu. Status in

[Openjdk] [Bug 551328] Re: Applets use 100% of CPU

2010-08-12 Thread Marc Deslauriers
** CVE removed: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2009-3555 -- Applets use 100% of CPU https://bugs.launchpad.net/bugs/551328 You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-6 in ubuntu. Status in OpenJDK: Confirmed Status

[Openjdk] [Bug 472845] Re: wrong metric for Chinese font in OpenJDK applications

2010-08-12 Thread Marc Deslauriers
** CVE removed: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2009-3555 -- wrong metric for Chinese font in OpenJDK applications https://bugs.launchpad.net/bugs/472845 You received this bug notification because you are a member of OpenJDK, which is subscribed to openjdk-6 in ubuntu. Status