This repository was archived by the owner on Apr 12, 2021. It is now read-only.
-
-
Notifications
You must be signed in to change notification settings - Fork 104
Permalink
Choose a base ref
{{ refName }}
default
Choose a head ref
{{ refName }}
default
Comparing changes
Choose two branches to see what’s changed or to start a new pull request.
If you need to, you can also or
learn more about diff comparisons.
Open a pull request
Create a new pull request by comparing changes across two branches. If you need to, you can also .
Learn more about diff comparisons here.
base repository: NixOS/nixpkgs-channels
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 6f7aca86f037
Could not load branches
Nothing to show
Loading
Could not load tags
Nothing to show
{{ refName }}
default
Loading
...
head repository: NixOS/nixpkgs-channels
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: e36f91fa8610
Could not load branches
Nothing to show
Loading
Could not load tags
Nothing to show
{{ refName }}
default
Loading
- 4 commits
- 1 file changed
- 2 contributors
Commits on Aug 15, 2019
-
icedtea_web: 1.7.1 -> 1.7.2 (plus CVE patches)
On Wed, 31 Jul 2019 it was announced that IcedTea-Web was affected by the below security vulnerabilities: - CVE-2019-10185: zip-slip attack during auto-extraction of a JAR file. - CVE-2019-10181: executable code could be injected in a JAR file without compromising the signature verification. - CVE-2019-10182: improper path sanitization from elements in JNLP files. Version 1.7 was patched, but no release was made. Moreover, the patches apply cleanly only to 1.7.2, not the current 1.7.1. Rather than marking 1.7.1 as insecure, update to 1.7.2 and apply the official patches. References: https://www.openwall.com/lists/oss-security/2019/07/31/2 AdoptOpenJDK/IcedTea-Web#327 AdoptOpenJDK/IcedTea-Web#346
Configuration menu - View commit details
-
Copy full SHA for f864ddf - Browse repository at this point
Copy the full SHA f864ddfView commit details -
icedtea-web: use glib build input instead of gtk2
gtk2 is not needed any more
Configuration menu - View commit details
-
Copy full SHA for eb01d7a - Browse repository at this point
Copy the full SHA eb01d7aView commit details -
icedtea-web: remove sh extension from launchers for back compat
icedtea-web 1.7.2 builds its launchers shell scripts with the "sh" extension, while version 1.7.1 did not. For backwards-compatibility, remove the extension from the executable in postInstall. Note that version 1.7.2 also creates a file called itw-modularjdk.args in the bin directory. This file is referenced by the shell launchers, so we leave it there (it's not executable anyway).
Configuration menu - View commit details
-
Copy full SHA for fc78b41 - Browse repository at this point
Copy the full SHA fc78b41View commit details -
Merge pull request #66444 from stefano-m/icedtea-web-1.7.2-cvefixes
icedtea_web: 1.7.1 -> 1.7.2 (plus CVE patches)
Configuration menu - View commit details
-
Copy full SHA for e36f91f - Browse repository at this point
Copy the full SHA e36f91fView commit details
There are no files selected for viewing