Thu, 24 Sep 2009 22:50:41 +0100 6863503: SECURITY: MessageDigest.isEqual introduces timing attack vulnerabilities
vinnie [Thu, 24 Sep 2009 22:50:41 +0100] rev 4208
6863503: SECURITY: MessageDigest.isEqual introduces timing attack vulnerabilities Reviewed-by: mullan, wetmore
Mon, 14 Sep 2009 11:46:16 +0400 6872358: JRE AWT setBytePixels vulnerable to Heap Overflow
bae [Mon, 14 Sep 2009 11:46:16 +0400] rev 4207
6872358: JRE AWT setBytePixels vulnerable to Heap Overflow Reviewed-by: prr, hawtin
Thu, 10 Sep 2009 14:15:47 +0400 6631533: ICC_Profile allows detecting if some files exist
bae [Thu, 10 Sep 2009 14:15:47 +0400] rev 4206
6631533: ICC_Profile allows detecting if some files exist Reviewed-by: prr, hawtin
Thu, 10 Sep 2009 14:04:38 +0400 6632445: DoS from parsing BMPs with UNC ICC links
bae [Thu, 10 Sep 2009 14:04:38 +0400] rev 4205
6632445: DoS from parsing BMPs with UNC ICC links Reviewed-by: prr, hawtin
(0) -3000 -1000 -300 -100 -30 -10 -4 +4 +10 +30 +100 +300 +1000 +3000 +10000 +30000 tip