openjdk-7-source - OpenJDK Development Kit (JDK) source files

OpenJDK is a development environment for building applications,
applets, and components using the Java programming language.
This package contains the Java programming language source files
( for all classes that make up the Java core API.
The packages are built using the IcedTea build support and patches
from the IcedTea project.


2018-10-11 - Tiago Stürmer Daitx <>
openjdk-7 (7u181-2.6.14-0ubuntu0.3) trusty-security; urgency=medium
* Apply 7u201-b00 security patches.
* Security fixes:
- CVE-2018-3136, S8194534: Manifest better support.
- CVE-2018-3139, S8196902: Better HTTP redirection support.
- CVE-2018-3149, S8199177: Enhance JNDI lookups.
- CVE-2018-3169, S8199226: Improve field accesses.
- CVE-2018-3180, S8202613: Improve TLS connections stability.
* debian/patches/jdk-freetypeScaler-crash.diff: removed, it caused
a memory leak and has been fixed upstream already, albeit in a
different way. Closes: #910672.
* debian/patches/jdk-8132985-backport-double-free.patch,
debian/patches/jdk-8139803-backport-warning.patch: fix crash in
freetypescaler due to double free, thanks to Heikki Aitakangas for
the report and patches. (Closes: #911847)
* debian/rules: run only the hotspot testsuite for jamvm and zero
alternative vms to make build faster.
2018-07-23 - Tiago Stürmer Daitx <>
openjdk-7 (7u181-2.6.14-0ubuntu0.2) trusty-security; urgency=medium
* Apply 8u181 security backports.
* Security fixes:
- CVE-2018-2938, S8197871: Support Derby connections.
- CVE-2018-2952, S8199547: Exception to Pattern Syntax.
- S8191239: Improve desktop file usage.
- S8193419: Better Internet address support.
- S8197925: Better stack walking.
- S8200666: Improve LDAP support.
* debian/patches/hotspot-S8207151-fix-bad-klassoop.patch: fix bug introduced
by the backport of S8189123. LP: #1778930.
2018-06-04 - Tiago Stürmer Daitx <>
openjdk-7 (7u181-2.6.14-0ubuntu0.1) trusty-security; urgency=medium
* IcedTea release 2.6.14 (based on 7u181). Closes: #898976.
* Security fixes:
- S8162488: JDK should be updated to use LittleCMS 2.8
- S8180881: Better packaging of deserialization
- S8182362: Update CipherOutputStream Usage
- S8183032: Upgrade to LittleCMS 2.9
- S8189123: More consistent classloading
- S8189969, CVE-2018-2790: Manifest better manifest entries
- S8189977, CVE-2018-2795: Improve permission portability
- S8189981, CVE-2018-2796: Improve queuing portability
- S8189985, CVE-2018-2797: Improve tabular data portability
- S8189989, CVE-2018-2798: Improve container portability
- S8189993, CVE-2018-2799: Improve document portability
- S8189997, CVE-2018-2794: Enhance keystore mechanisms
- S8190478: Improved interface method selection
- S8190877: Better handling of abstract classes
- S8191696: Better mouse positioning
- S8192025, CVE-2018-2814: Less referential references
- S8192030: Better MTSchema support
- S8192757, CVE-2018-2815: Improve stub classes implementation
- S8193409: Improve AES supporting classes
- S8193414: Improvements in MethodType lookups
- S8193833, CVE-2018-2800: Better RMI connection support
* debian/patches/hotspot-disable-exec-shield-workaround.patch: removed,
upstream fixed i386 stack guard support in S8197429 (hotspot's mercurial
commit 6636:d673ec579604).
* debian/patches/hotspot-powerpcspe.diff: removed, support added upstream by
S8186461 in hotspot's mercurial commit 6638:7517e77dd338.
* debian/patches/it-patch-updates.diff: remove unnecessary hunks.
* debian/rules: remove hotspot-powerpcspe.diff and
hotspot-disable-exec-shield-workaround.patch from applied patches.

