File _patchinfo of Package patchinfo

<patchinfo incident="java-1_6_0-openjdk">
  <packager>lijews</packager>
  <issue tracker="cve" id="CVE-2013-1500"></issue>
  <issue tracker="cve" id="CVE-2013-1571"></issue>
  <issue tracker="cve" id="CVE-2013-2407"></issue>
  <issue tracker="cve" id="CVE-2013-2412"></issue>
  <issue tracker="cve" id="CVE-2013-2443"></issue>
  <issue tracker="cve" id="CVE-2013-2444"></issue>
  <issue tracker="cve" id="CVE-2013-2445"></issue>
  <issue tracker="cve" id="CVE-2013-2446"></issue>
  <issue tracker="cve" id="CVE-2013-2447"></issue>
  <issue tracker="cve" id="CVE-2013-2448"></issue>
  <issue tracker="cve" id="CVE-2013-2450"></issue>
  <issue tracker="cve" id="CVE-2013-2451"></issue>
  <issue tracker="cve" id="CVE-2013-2452"></issue>
  <issue tracker="cve" id="CVE-2013-2453"></issue>
  <issue tracker="cve" id="CVE-2013-2455"></issue>
  <issue tracker="cve" id="CVE-2013-2456"></issue>
  <issue tracker="cve" id="CVE-2013-2457"></issue>
  <issue tracker="cve" id="CVE-2013-2459"></issue>
  <issue tracker="cve" id="CVE-2013-2461"></issue>
  <issue tracker="cve" id="CVE-2013-2463"></issue>
  <issue tracker="cve" id="CVE-2013-2465"></issue>
  <issue tracker="cve" id="CVE-2013-2469"></issue>
  <issue tracker="cve" id="CVE-2013-2470"></issue>
  <issue tracker="cve" id="CVE-2013-2471"></issue>
  <issue tracker="cve" id="CVE-2013-2472"></issue>
  <issue tracker="cve" id="CVE-2013-2473"></issue>
  <category>security</category>
  <rating>moderate</rating>
  <summary>java-1_6_0-openjdk: security update to IcedTea 1.12.6</summary>
  <description>These releases update our OpenJDK 6 support to include the latest security updates. 

The security fixes are as follows:

 * S6741606, CVE-2013-2407: Integrate Apache Santuario
 * S7158805, CVE-2013-2445: Better rewriting of nested subroutine calls
 * S7170730, CVE-2013-2451: Improve Windows network stack support.
 * S8000638, CVE-2013-2450: Improve deserialization
 * S8000642, CVE-2013-2446: Better handling of objects for transportation
 * S8001032: Restrict object access
 * S8001033, CVE-2013-2452: Refactor network address handling in virtual machine identifiers
 * S8001034, CVE-2013-1500: Memory management improvements
 * S8001038, CVE-2013-2444: Resourcefully handle resources
 * S8001043: Clarify definition restrictions
 * S8001309: Better handling of annotation interfaces
 * S8001318, CVE-2013-2447: Socket.getLocalAddress not consistent with InetAddress.getLocalHost
 * S8001330, CVE-2013-2443: Improve on checking order
 * S8003703, CVE-2013-2412: Update RMI connection dialog box
 * S8004584: Augment applet contextualization
 * S8005007: Better glyph processing
 * S8006328, CVE-2013-2448: Improve robustness of sound classes
 * S8006611: Improve scripting
 * S8007467: Improve robustness of JMX internal APIs
 * S8007471: Improve MBean notifications
 * S8007812, CVE-2013-2455: (reflect) Class.getEnclosingMethod problematic for some classes
 * S8008120, CVE-2013-2457: Improve JMX class checking
 * S8008124, CVE-2013-2453: Better compliance testing
 * S8008128: Better API coherence for JMX
 * S8008132, CVE-2013-2456: Better serialization support
 * S8008585: Better JMX data handling
 * S8008593: Better URLClassLoader resource management
 * S8008603: Improve provision of JMX providers
 * S8008611: Better handling of annotations in JMX
 * S8008615: Improve robustness of JMX internal APIs
 * S8008623: Better handling of MBeanServers
 * S8008744, CVE-2013-2407: Rework part of fix for JDK-6741606
 * S8008982: Adjust JMX for underlying interface changes
 * S8009004: Better implementation of RMI connections
 * S8009013: Better handling of T2K glyphs
 * S8009034: Improve resulting notifications in JMX
 * S8009038: Improve JMX notification support
 * S8009067: Improve storing keys in KeyStore
 * S8009071, CVE-2013-2459: Improve shape handling
 * S8009235: Improve handling of TSA data
 * S8011243, CVE-2013-2470: Improve ImagingLib
 * S8011248, CVE-2013-2471: Better Component Rasters
 * S8011253, CVE-2013-2472: Better Short Component Rasters
 * S8011257, CVE-2013-2473: Better Byte Component Rasters
 * S8012375, CVE-2013-1571: Improve Javadoc framing
 * S8012421: Better positioning of PairPositioning
 * S8012438, CVE-2013-2463: Better image validation
 * S8012597, CVE-2013-2465: Better image channel verification
 * S8012601, CVE-2013-2469: Better validation of image layouts
 * S8014281, CVE-2013-2461: Better checking of XML signature
 * S8015997: Additional improvement in Javadoc framing</description>
</patchinfo>
openSUSE Build Service is sponsored by