File _patchinfo of Package patchinfo.1031

<patchinfo incident="1031">
  <packager>mvyskocil</packager>
  <issue tracker="bnc" id="785814">VUL-0: java-1_7_0-openjdk: multiple vulnerabilites (tracker bug)</issue>
  <issue tracker="cve" id="CVE-2012-5068"></issue>
  <issue tracker="cve" id="CVE-2012-3216"></issue>
  <issue tracker="cve" id="CVE-2012-5070"></issue>
  <issue tracker="cve" id="CVE-2012-5086"></issue>
  <issue tracker="cve" id="CVE-2012-4416"></issue>
  <issue tracker="cve" id="CVE-2012-5088"></issue>
  <issue tracker="cve" id="CVE-2012-5087"></issue>
  <issue tracker="cve" id="CVE-2012-5084"></issue>
  <issue tracker="cve" id="CVE-2012-5085"></issue>
  <issue tracker="cve" id="CVE-2012-5071"></issue>
  <issue tracker="cve" id="CVE-2012-5089"></issue>
  <issue tracker="cve" id="CVE-2012-5074"></issue>
  <issue tracker="cve" id="CVE-2012-5069"></issue>
  <issue tracker="cve" id="CVE-2012-5075"></issue>
  <issue tracker="cve" id="CVE-2012-5073"></issue>
  <issue tracker="cve" id="CVE-2012-5077"></issue>
  <issue tracker="cve" id="CVE-2012-5076"></issue>
  <category>security</category>
  <rating>important</rating>
  <summary>java-1_7_0-openjdk: Update to icedtea-2.3.3</summary>
  <description>java-1_7_0-opendjk was updated to icedtea-2.3.3 (bnc#785814)
* Security fixes
  - S6631398, CVE-2012-3216: FilePermission improved path checking
  - S7093490: adjust package access in rmiregistry
  - S7143535, CVE-2012-5068: ScriptEngine corrected permissions
  - S7158796, CVE-2012-5070: Tighten properties checking in EnvHelp
  - S7158807: Revise stack management with volatile call sites
  - S7163198, CVE-2012-5076: Tightened package accessibility
  - S7167656, CVE-2012-5077: Multiple Seeders are being created
  - S7169884, CVE-2012-5073: LogManager checks do not work correctly for sub-types
  - S7169887, CVE-2012-5074: Tightened package accessibility
  - S7169888, CVE-2012-5075: Narrowing resource definitions in JMX RMI connector
  - S7172522, CVE-2012-5072: Improve DomainCombiner checking
  - S7186286, CVE-2012-5081: TLS implementation to better adhere to RFC
  - S7189103, CVE-2012-5069: Executors needs to maintain state
  - S7189490: More improvements to DomainCombiner checking
  - S7189567, CVE-2012-5085: java net obselete protocol
  - S7192975, CVE-2012-5071: Issue with JMX reflection
  - S7195194, CVE-2012-5084: Better data validation for Swing
  - S7195549, CVE-2012-5087: Better bean object persistence
  - S7195917, CVE-2012-5086: XMLDecoder parsing at close-time should be improved
  - S7195919, CVE-2012-5079: (sl) ServiceLoader can throw CCE without needing to create instance
  - S7196190, CVE-2012-5088: Improve method of handling MethodHandles
  - S7198296, CVE-2012-5089: Refactor classloader usage
  - S7158800: Improve storage of symbol tables
  - S7158801: Improve VM CompileOnly option
  - S7158804: Improve config file parsing
  - S7198606, CVE-2012-4416: Improve VM optimization
* Bug fixes
  - Remove merge artefact.</description>
</patchinfo>
openSUSE Build Service is sponsored by