Tue, 06 Apr 2010 15:45:21 -0700 6717164: FilterInputStream.skip incorrectly inherits wording specifying how the InputStream.skip works
sherman [Tue, 06 Apr 2010 15:45:21 -0700] rev 5201
6717164: FilterInputStream.skip incorrectly inherits wording specifying how the InputStream.skip works Summary: restoring the javadoc Reviewed-by: alanb
Tue, 06 Apr 2010 15:44:17 +0100 6921111: NullPointerException in PlainDatagramSocketImpl.socketSetOption
chegar [Tue, 06 Apr 2010 15:44:17 +0100] rev 5200
6921111: NullPointerException in PlainDatagramSocketImpl.socketSetOption Reviewed-by: alanb
Tue, 06 Apr 2010 13:47:59 +0100 6648001: Cancelling HTTP authentication causes subsequent deadlocks
chegar [Tue, 06 Apr 2010 13:47:59 +0100] rev 5199
6648001: Cancelling HTTP authentication causes subsequent deadlocks Reviewed-by: michaelm
Mon, 05 Apr 2010 16:11:59 -0700 Merge
asaha [Mon, 05 Apr 2010 16:11:59 -0700] rev 5198
Merge
Mon, 29 Mar 2010 07:17:02 -0700 Merge
asaha [Mon, 29 Mar 2010 07:17:02 -0700] rev 5197
Merge
Thu, 25 Mar 2010 07:12:43 -0700 Merge
asaha [Thu, 25 Mar 2010 07:12:43 -0700] rev 5196
Merge
Wed, 24 Mar 2010 17:32:04 -0700 Merge
asaha [Wed, 24 Mar 2010 17:32:04 -0700] rev 5195
Merge
Wed, 24 Mar 2010 14:16:57 -0700 Merge
asaha [Wed, 24 Mar 2010 14:16:57 -0700] rev 5194
Merge
Sat, 06 Mar 2010 03:37:53 +0300 6932659: JTreg test files were missed in push of 6887703
denis [Sat, 06 Mar 2010 03:37:53 +0300] rev 5193
6932659: JTreg test files were missed in push of 6887703 Reviewed-by: uta
Fri, 26 Feb 2010 03:54:52 -0800 6887703: Unsigned applet can retrieve the dragged information before drop action occur
denis [Fri, 26 Feb 2010 03:54:52 -0800] rev 5192
6887703: Unsigned applet can retrieve the dragged information before drop action occur Reviewed-by: uta
Mon, 22 Feb 2010 14:33:19 -0800 6902299: Java JAR "unpack200" must verify input parameters
ksrini [Mon, 22 Feb 2010 14:33:19 -0800] rev 5191
6902299: Java JAR "unpack200" must verify input parameters Summary: Added several checks for addition of values before memory allocation Reviewed-by: asaha
Fri, 19 Feb 2010 22:30:52 +0300 6899653: Sun Java Runtime CMM readMabCurveData Buffer Overflow Vulnerability
bae [Fri, 19 Feb 2010 22:30:52 +0300] rev 5190
6899653: Sun Java Runtime CMM readMabCurveData Buffer Overflow Vulnerability Reviewed-by: prr, hawtin
Wed, 17 Feb 2010 13:32:26 +0300 6909597: Sun Java Runtime Environment JPEGImageReader stepX Integer Overflow Vulnerability
bae [Wed, 17 Feb 2010 13:32:26 +0300] rev 5189
6909597: Sun Java Runtime Environment JPEGImageReader stepX Integer Overflow Vulnerability Reviewed-by: igor
Wed, 17 Feb 2010 13:10:26 +0300 6914823: Java AWT Library Invalid Index Vulnerability
bae [Wed, 17 Feb 2010 13:10:26 +0300] rev 5188
6914823: Java AWT Library Invalid Index Vulnerability Reviewed-by: flar, hawtin
Wed, 17 Feb 2010 12:49:41 +0300 6914866: Sun JRE ImagingLib arbitrary code execution vulnerability
bae [Wed, 17 Feb 2010 12:49:41 +0300] rev 5187
6914866: Sun JRE ImagingLib arbitrary code execution vulnerability Reviewed-by: prr, hawtin
Tue, 12 Jan 2010 12:13:48 +0000 6910590: Application can modify command array, in ProcessBuilder
michaelm [Tue, 12 Jan 2010 12:13:48 +0000] rev 5186
6910590: Application can modify command array, in ProcessBuilder Summary: clone array returned by List.toArray() Reviewed-by: chegar, alanb
Tue, 22 Dec 2009 17:56:58 +0300 6904691: Java Applet Trusted Methods Chaining Privilege Escalation Vulnerability
malenkov [Tue, 22 Dec 2009 17:56:58 +0300] rev 5185
6904691: Java Applet Trusted Methods Chaining Privilege Escalation Vulnerability Reviewed-by: hawtin, peterz
Fri, 18 Dec 2009 09:09:12 -0500 6904162: Add new VeriSign root CA certificates to JRE and remove some old/unused ones
mullan [Fri, 18 Dec 2009 09:09:12 -0500] rev 5184
6904162: Add new VeriSign root CA certificates to JRE and remove some old/unused ones Reviewed-by: asaha
Tue, 08 Dec 2009 15:58:49 -0500 6633872: Policy/PolicyFile leak dynamic ProtectionDomains.
mullan [Tue, 08 Dec 2009 15:58:49 -0500] rev 5183
6633872: Policy/PolicyFile leak dynamic ProtectionDomains. Reviewed-by: hawtin
Mon, 07 Dec 2009 21:16:41 -0800 6898739: TLS renegotiation issue
xuelei [Mon, 07 Dec 2009 21:16:41 -0800] rev 5182
6898739: TLS renegotiation issue Summary: the interim fix disables TLS/SSL renegotiation Reviewed-by: mullan, chegar, wetmore
Fri, 04 Dec 2009 10:23:07 -0800 Merge
asaha [Fri, 04 Dec 2009 10:23:07 -0800] rev 5181
Merge
Wed, 02 Dec 2009 12:17:42 +0000 6893954: Subclasses of InetAddress may incorrectly interpret network addresses
michaelm [Wed, 02 Dec 2009 12:17:42 +0000] rev 5180
6893954: Subclasses of InetAddress may incorrectly interpret network addresses Summary: runtime type checks and deserialization check Reviewed-by: chegar, alanb, jccollet
Tue, 01 Dec 2009 08:55:15 -0800 Merge
asaha [Tue, 01 Dec 2009 08:55:15 -0800] rev 5179
Merge
Thu, 26 Nov 2009 07:17:08 -0800 Merge
asaha [Thu, 26 Nov 2009 07:17:08 -0800] rev 5178
Merge
Wed, 25 Nov 2009 16:02:08 -0800 Merge
mchung [Wed, 25 Nov 2009 16:02:08 -0800] rev 5177
Merge
Wed, 25 Nov 2009 11:19:32 -0800 Merge
mchung [Wed, 25 Nov 2009 11:19:32 -0800] rev 5176
Merge
Wed, 25 Nov 2009 09:09:04 -0800 6893947: Deserialization of RMIConnectionImpl objects should enforce stricter checks [ZDI-CAN-588]
mchung [Wed, 25 Nov 2009 09:09:04 -0800] rev 5175
6893947: Deserialization of RMIConnectionImpl objects should enforce stricter checks [ZDI-CAN-588] Summary: narrow the doPrivileged block to only set context ClassLoader Reviewed-by: hawtin, emcmanus
Wed, 25 Nov 2009 12:51:00 -0800 6904925: Changeset for 6745393 for jdk7 ssr forest was incomplete
sherman [Wed, 25 Nov 2009 12:51:00 -0800] rev 5174
6904925: Changeset for 6745393 for jdk7 ssr forest was incomplete Summary: To add, commit and push back the ZStreamRef.java Reviewed-by: alanb
Wed, 25 Nov 2009 11:29:23 -0800 6745393: Inflater/Deflater clone issue
sherman [Wed, 25 Nov 2009 11:29:23 -0800] rev 5173
6745393: Inflater/Deflater clone issue Summary: To use explicit lobk object. Reviewed-by: alanb
Wed, 25 Nov 2009 10:02:50 +0000 6736390: File TOCTOU deserialization vulnerability
alanb [Wed, 25 Nov 2009 10:02:50 +0000] rev 5172
6736390: File TOCTOU deserialization vulnerability Reviewed-by: hawtin
Mon, 23 Nov 2009 12:40:46 +0000 6639665: ThreadGroup finalizer allows creation of false root ThreadGroups
chegar [Mon, 23 Nov 2009 12:40:46 +0000] rev 5171
6639665: ThreadGroup finalizer allows creation of false root ThreadGroups Reviewed-by: alanb, hawtin
Fri, 20 Nov 2009 14:24:56 -0800 Merge
asaha [Fri, 20 Nov 2009 14:24:56 -0800] rev 5170
Merge
(0) -3000 -1000 -300 -100 -50 -32 +32 +50 +100 +300 +1000 +3000 +10000 +30000 tip