What's up with java and security?

Alfred Perlstein alfred at freebsd.org
Mon May 16 20:34:22 PDT 2005


I wanted to play with java, but it looks like all the ports we
have are busted...

jdk13 native has issues:
===>  jdk-1.3.1p9_5 has known vulnerabilities:
=> jdk/jre -- Security Vulnerability With Java Plugin.
   Reference: <http://www.FreeBSD.org/ports/portaudit/ac619d06-3ef8-11d9-8741-c942c075aa41.html>


jdk14 depends on linux-sun-jdk14 which has issues:
===>  linux-sun-jdk-1.4.2.08_1 has known vulnerabilities:
=> jdk -- jar directory traversal vulnerability.
   Reference: <http://www.FreeBSD.org/ports/portaudit/18e5428f-ae7c-11d9-837d-000e0c2e438a.html>

Is Sun planning on fixing this?

-- 
- Alfred Perlstein
- Research Engineering Development Inc.
- email: bright at mu.org cell: 408-480-4684


More information about the freebsd-java mailing list