Automatic conversion of the NetBSD pkgsrc CVS module, use with care
Find a file
obache 43b59b95a4 Update sun-{jre,jdk}15 to 1.5.0.20.
Changes in 1.5.0_20

The full internal version number for this update release is 1.5.0_20-b02 (where
"b" means "build"). The external version number is 5.0u20.
OlsonData 2009i

This release contains Olson time zone data version 2009i. For more information,
refer to Timezone Data Versions in the JRE Software .

Security Baseline

This update release specifies the following security baseline:
JRE Family Version 	Java SE
Security Baseline 	Java SE for Business
Security Baseline 1.4.2 	1.4.2_19 	1.4.2_22

In December, 2008, Java SE 1.4.2 reached its end of service life with the
release of 1.4.2_19. Future revisions of Java SE 1.4.2 (1.4.2_20 and above)
include the Access Only option and are available to Java SE for Business
subscribers.

For more information about the security baseline, see Deploying Java Applets
With Family JRE Versions in Java Plug-in for Internet Explorer .

Root Certificates

Root Certificates are included in this release.

    * Added one new root certificate and removed 3 root certificates from Entrust. (Refer to 6805338.)
    * Added three new root certificates from Keynectis. (Refer to 6845457.)
    * Added three new root certificates from Quovadis. (Refer to 6846473.)

Bug Fixes

This release contains fixes for one or more security vulnerabilities. For more
information, please see Sun Alerts 263408 , 263409 , 263488 , 263489 , and 264648.

Bug fixes for vulnerabilities are listed in the following table.
	BugId 	Category 	Subcategory 	Description 6656610 	java 	accessibility 	AccessibleResourceBundle.getContents exposes mutable static (findbugs)
6656586 	java 	classes_awt 	Cursor.predefined is protected static mutable (findbugs)
6660539 	java 	classes_beans 	Introspector cache mutable static
6446522 	java 	classes_lang 	3Y Race condition in reflection checks
6801071 	java 	classes_net 	Remote sites can compromise user privacy and possibly hijack web session
6801497 	java 	classes_net 	Proxy is assumed to be immutable but is non-final
6406003 	java 	classes_security 	Security issues in the Provider class
6429594 	java 	classes_security 	Fix for 6406003 can be circumvented
6444262 	java 	classes_security 	Provider deserialization still has problems
6657695 	java 	classes_security 	AbstractSaslImpl.logger is a static mutable (findbugs)
6657625 	java 	classes_sound 	RmfFileReader/StandardMidiFileWriter.types are public mutable statics (findbugs)
6738524 	java 	classes_sound 	JDK13Services allows read access to system properties from untrusted code
6777448 	java 	classes_sound 	JDK13Services.getProviders creates instances with full privileges
6588003 	java 	classes_swing 	LayoutQueue mutable statics
6660049 	java 	classes_swing 	Synth Region.uiToRegionMap/lowerCaseNameMap are mutable statics
6656625 	java 	imageio 	ImageReaderSpi.STANDARD_INPUT_TYPE/ImageWriterSpi.STANDARD_OUTPUT_TYPE are mutable static (findbugs)
6657133 	java 	imageio 	Mutable statics in imageio plugins (findbugs)
6830335 	java 	jar 	Java JAR Pack200 Decompression Integer Overflow Vulnerability
6862844 	javawebstart 	other 	java web start ActiveX control security problem caused by ATL PROP_ENTRY macro
6845701 	jaxp 	parse 	Xerces2 Java XML library infinite loop with malformed XML input
6657619 	jndi 	dns 	DnsContext.debug is public static mutable (findbugs)

Other bug fixes are listed in the following table.
	BugId 	Category 	Subcategory 	Description 6851379 	java 	classes_2d 	font files not deleted upon exit
6805338 	java 	classes_security 	Add 1 new Entrust root CA cert and remove 3 others with 1024 bit keys
6845457 	java 	classes_security 	Add root certs for Keynectis CA
6846473 	java 	classes_security 	Add QuoVadis root CA certs to the JRE
6848984 	java 	classes_util_i18n 	(tz) Support tzdata2009i
6851214 	java 	classes_util_i18n 	(tz) New Jordan rule creates a failure for SimpleTimeZone parsing post tzdata2009h
2009-08-20 08:46:40 +00:00
archivers Update to 1.22: 2009-08-16 13:53:32 +00:00
audio not for python-2.4, because support was dropped from py-gtk2 2009-08-19 11:34:34 +00:00
benchmarks emove empty PLIST. 2009-07-22 09:23:13 +00:00
biology Update to 14.4: 2009-08-09 23:15:43 +00:00
bootstrap Add /usr/bsd to $overpath for IRIX as per PR 38802. I'm going to leave 2009-08-01 20:19:37 +00:00
cad Update to boolean-6.99. No changes, but supports wxGTK 2.8. 2009-08-14 19:09:48 +00:00
chat Change dependency pattern for devel/tre from tre-0.7.5 to tre>=0.7.5. 2009-08-19 08:17:59 +00:00
comms Update to 1.6.1.4. This fixes AST-2009-005, which is a DOS problem with 2009-08-12 03:27:48 +00:00
converters Add a patch to avoid conflict with getline(3). 2009-08-11 15:01:14 +00:00
cross Make it build on recent DragonFly. 2009-08-01 05:22:38 +00:00
databases Updating package databases/p5-Rose-DB from 0.752 to 0.753 2009-08-19 20:42:18 +00:00
devel Updating package devel/p5-TAP-Harness-Archive from 0.13 to 0.14 2009-08-20 05:36:16 +00:00
distfiles
doc Updated devel/p5-TAP-Harness-Archive to 0.14 2009-08-20 05:36:28 +00:00
editors Update to 0.1.2. 2009-08-19 14:43:36 +00:00
emulators Update to 0.133. Sadly, patches can't be shared with sdlmame any longer, 2009-08-15 17:23:59 +00:00
filesystems fuse_main for FUSE 2.6 has the signature of the !NetBSD branch, so drop 2009-08-03 13:57:14 +00:00
finance Remove USE_DIRS from pkgsrc. 2009-07-22 09:01:16 +00:00
fonts Add description of patch. 2009-08-11 14:59:09 +00:00
games Make this build on Mac OS X. Fixed PR pkg/41538. 2009-08-19 04:04:40 +00:00
geography Remove postgresql81-postgis here as well. 2009-08-17 07:57:48 +00:00
graphics * Make it link on DragonFly and maybe some others (sane_find_scanner needs 2009-08-20 03:53:20 +00:00
ham Fix PLIST. Bump revision. 2009-08-18 15:53:18 +00:00
inputmethod MAKE_JOBS_SAFE=no 2009-08-18 15:51:17 +00:00
lang Update sun-{jre,jdk}15 to 1.5.0.20. 2009-08-20 08:46:40 +00:00
licenses Add mpl-1.0 (Mozilla Public License), and allow it by default. 2009-07-26 09:18:29 +00:00
mail Updated p5-GD-Graph3d dependency. 2009-08-17 19:09:13 +00:00
math Updating package for p5 module Statistics::Descriptive from 2.6 to 3.0100 2009-08-18 14:03:06 +00:00
mbone Fix destdir installation 2009-08-18 15:57:59 +00:00
meta-pkgs not for python-2.4, because support was dropped from py-gtk2 2009-08-19 11:34:34 +00:00
misc Updating misc/p5-App-MrShell from 2.0200 to 2.0205 2009-08-19 19:55:01 +00:00
mk Remove unused options: w3m-m17n and w3m-unicode. 2009-08-19 06:18:42 +00:00
multimedia add build dependencies on xmlto and zip, from Robert Elz per PR pkg/41907 2009-08-19 08:44:06 +00:00
net Updating package net/p5-Data-Stream-Bulk from 0.03 to 0.07 2009-08-19 19:50:16 +00:00
news Fix a core dump when listing an mhbox thread. 2009-07-22 10:53:51 +00:00
packages
parallel Fix installed manual pages to correctly refer to SGE rather than GE. 2009-08-19 09:56:22 +00:00
pkgtools Pass down MAKE_ENV when calling make for inplace builds. 2009-08-17 18:43:49 +00:00
print Update to 5.2.4 from Bernd Ernesti. 2009-08-19 00:19:06 +00:00
regress Remove @dirrm entries from PLISTs 2009-06-14 18:11:52 +00:00
security Updating security/p5-IO-Socket-SSL from 1.27 to 1.30 2009-08-20 05:32:21 +00:00
shells remove ftp.gw.com from master_sites. service suspended. 2009-08-15 23:43:26 +00:00
sysutils not for python-2.4, because support was dropped from py-gtk2 2009-08-19 11:34:34 +00:00
templates audit-packages is now in pkg_install on pkgsrc HEAD and stable so update 2008-12-10 22:06:48 +00:00
textproc Update to mdocml-1.9.0: 2009-08-19 14:44:34 +00:00
time Updating package time/p5-MooseX-Types-DateTime from 0.03 to 0.04 2009-08-19 06:19:12 +00:00
wm turn ImageMagick/bl3 inclusion into a simple DEPENDS, nothing 2009-08-11 12:12:34 +00:00
www Updating package www/p5-FCGI-ProcManager from 0.18nb1 to 0.19 2009-08-19 19:11:48 +00:00
x11 not for python-2.4, because support was dropped from py-gnome2 2009-08-19 14:25:27 +00:00
Makefile cleanup 2009-05-16 07:21:05 +00:00
pkglocate
README

$NetBSD: README,v 1.18 2005/05/07 22:18:28 wiz Exp $

Please see doc/pkgsrc.txt for information.