atom feed15 messages in net.java.dev.jugs.jug-leaders[jug-leaders] Re: Java 7 0day
FromSent OnAttachments
Tobias FrechAug 27, 2012 4:55 am 
John YearyAug 28, 2012 6:49 am 
Víctor OrozcoAug 28, 2012 8:46 am 
Hildeberto MendonçaAug 30, 2012 12:34 am 
John YearyAug 30, 2012 5:27 am 
Víctor OrozcoAug 31, 2012 3:46 pm 
Georges SaabSep 1, 2012 11:04 pm 
Frans ThamuraSep 1, 2012 11:19 pm 
Mattias KarlssonSep 11, 2012 5:51 am 
Frans ThamuraSep 11, 2012 5:56 am 
Donald SmithSep 11, 2012 6:01 am 
Tobias FrechSep 11, 2012 9:27 am 
Donald SmithSep 11, 2012 9:35 am 
Toth, CsabaSep 11, 2012 12:53 pm 
Hildeberto MendonçaSep 12, 2012 12:48 am 
Subject:[jug-leaders] Re: Java 7 0day
From:Georges Saab (geor@oracle.com)
Date:Sep 1, 2012 11:04:25 pm
List:net.java.dev.jugs.jug-leaders

Hi Victor,

On 28 aug 2012, at 08:47, Víctor Orozco <caba@gmail.com> wrote:

In Linux distributions root privilege escalations are more common than the
people believes but the difference resides in the fact that you can expect a
patch in two or three days (as much) and the idea that I received from the
sentence "Oracle has yet to comment on the reports or say when it plans to fix
the vulnerability. The next scheduled patch release isn't until the middle of
October" is not very comforting. Maybe Oracle have to improve his public
relationships concerning to security issues :).

The Oracle policy has a bit more nuance than this -- for reference it can be
found here:

http://www.oracle.com/us/support/assurance/fixing-policies/index.html

btw, I am not trying to suggest that the policy is perfect, just to facilitate
knowing what it actually is.