[22979] in bugtraq
Re: Sun Security Bulletin #00208
daemon@ATHENA.MIT.EDU (Stanley G. Bubrouski)
Wed Oct 24 13:30:41 2001
Date: Wed, 24 Oct 2001 09:30:03 -0400 (EDT)
From: "Stanley G. Bubrouski" <stan@ccs.neu.edu>
To: Jay Sekora <jay@ccs.neu.edu>
Cc: bugtraq@securityfocus.com, "Jay D. Dyson" <jdyson@treachery.net>
In-Reply-To: <200110231706.f9NH6rj04927@amber.ccs.neu.edu>
Message-ID: <Pine.GSO.4.21.0110240928470.1266-100000@denali.ccs.neu.edu>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Jay,
It appears it affects all versions of JDK before 1.3.1x...
Regards,
Stan
--
Stan Bubrouski stan@ccs.neu.edu
23 Westmoreland Road, Hingham, MA 02043 Cell: (617) 835-3284
On Tue, 23 Oct 2001, Jay Sekora wrote:
> >From the Sun Security Bulletin:
> > 2. Affected Releases
> >
> > The following releases are affected:
>
> [...]
>
> > Solaris OE Production Releases
> >
> > SDK and JRE 1.3.0_02 or earlier
> > SDK and JRE 1.2.2_07 or earlier
> > SDK and JRE 1.2.1
> > SDK and JRE 1.2
>
> The version of the JDK that is shipped with Solaris 8 4/01 is
> (according to "/bin/java -version") "build Solaris_JDK_1.2.2_07a".
> Note trailing "a". Does anybody know for certain whether that counts
> as "SDK and JRE 1.2.2_07 or earlier" for purposes of this discussion?
> (We do lots of Java coursework here, and I'd prefer not to upgrade
> under people while school is in session if it can safely be avoided.)
>
> Sincerely,
>
> Jay Sekora
> for <systems@ccs.neu.edu>
>