Sun Release JDK 1.5 Update 15 (JDK

Bug fixes are listed in the following table.

BugId Category Subcategory Description
6587132 hotspot compiler2 Code changes behavior when compiled
6317397 hotspot runtime_system Hard hangs in concurrent code on Solaris and Linux
6633265 java classes_2d KCMS crash due to heap buffer out-of-bounds write with para-type curves
6633278 java classes_2d KCMS crash due heap-based buffer overflow parsing curv-type curves
6660717 java classes_2d KCMS crash due to heap buffer out-of-bounds write with para-type curves
6629657 java classes_awt provide raw key code from underlying system without changing API.
6632169 java classes_net HttpClient and HttpsClient should not try to reverse lookup IP address of a proxy server
6647251 java classes_security Add DigiCert root CA certs to JDK
6647254 java classes_security Add TrustCenter root CA certificates to the JDK
6651160 java classes_security Add AOL root CA certs to JDK
6624769 java classes_util_i18n (tz) Support tzdata2007i
6646197 java classes_util_i18n (tz) Support tzdata2007k
6374379 java classes_util_jarzip ZipFile class cannot open zip files with long filenames
6423026 java classes_util_jarzip doesn’t allow more than 2036 zip files to be concurrently open on Windows
6609756 java_deployment security Buffer Overflow in Java ActiveX component
6608712 java_plugin applet_spec Bypassing the same origin policy in Java with crafted names
6568419 java_plugin misc initial_focus flag not working when an applet is compiled with 1.4 and run with 1.5
6593309 java_plugin misc applet focus issue with button after minimizing an maximizing
6631506 java_plugin plugin REG : Unable to launch an applet on MZ using 6u4
6634129 java_plugin plugin jar protocol allows LiveConnect code to connect to any port on localhost
6623233 javawebstart general arbitary code execution using java web start
6605184 javawebstart jnlp_file [ZDI-CAN-234] Security Vulnerability in XML UTF8 character encoding in JNLP files
6660121 javawebstart jnlp_file Encoding values in JNLP files can cause buffer overflow
6588002 jaxp other XSLTProcessorApplet still allows reading from forbidden URLs
6616825 jmx classes JMX query returns no value in 1.0 compatibility mode – deserialization bug in readObject()

