[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Beginner's Question on Java Security Fixes



On Wed, May 8, 2013 at 2:16 PM, Markus Karg wrote:

> Maybe there is a misunderstanding. I am running Debian Wheezy, neither jessie nor sid. Certainly I want the best stability and security. Using Oracle's product, this would result in manually installing 7u21. But what if using openjdk-7-jre on wheezy? The version tag says it is 7u3, but I doubt that none of Oracle's fixes done between 7u3 and 7u21 is found in Wheezy. That's the problem I have. Everywhere Oracle says "since 7u21 it's safe", but I just cannot see whether this holds true for Wheezy's 7u3+?

Correct, none of the 7u21 fixes are in 7u3. I believe the plan is to
add 7u21 to wheezy because Oracle doesn't release fine-grained fixes,
but I'm not sure when that will happen. It should be possible for you
to install openjdk-7 from jessie on wheezy though, since they haven't
diverged much yet.

-- 
bye,
pabs

http://wiki.debian.org/PaulWise
http://bonedaddy.net/pabs3/


Reply to: