United StatesChange Country, Oracle Worldwide Web Sites Communities I am a... I want to...

Update Release Notes

Update Release Notes Index JDK Documentation

Update Release Notes Index

Update Release Notes Index

Changes in 1.6.0_17 (6u17)

The full internal version number for this update release is 1.6.0_17-b04 (where "b" means "build"). The external version number is 6u17.

OlsonData 2009m

6u17 contains Olson time zone data version 2009m. For more information, refer to Timezone Data Versions in the JRE Software .

Security Baseline

6u17 specifies the following security baselines for use with Java Plug-in technology:

JRE Family VersionJava SE
Security Baseline
Java SE for Business
Security Baseline
61.6.0_171.6.0_17
5.01.5.0_221.5.0_22
1.4.21.4.2_191.4.2_24

On October 30, 2008, Java SE 1.4.2 reached its end of service life with the release of 1.4.2_19. Future revisions of Java SE 1.4.2 (1.4.2_20 and above) include the Access Only option and are available to Java SE for Business subscribers.

For more information about the security baseline, see Deploying Java Applets With Family JRE Versions in Java Plug-in for Internet Explorer .

Root Certificates

Root Certificates are included in this release.

  • Added one new root certificate for SECOM. (Refer to 6872579.)
  • Added one new root certificate for GlobalSign. (Refer to 6860447.)


Blacklist Entries

There are no new blacklist entries in this update release.

Bug Fixes

This release contains fixes for one or more security vulnerabilities. For more information, please see Sun Alerts 269868, 269869, 269870, 270474, 270475, and 270476.

Bug fixes for vulnerabilities are listed in the following table.

BugIdCategorySubcategoryDescription
6631533 javaclasses_2dICC_Profile allows detecting if some files exist
6815780 javaclasses_2dTrueType font parsing crash when stressing Sun Bug 6751322 test case
6822057 javaclasses_2dX11 and Win32GraphicsDevice don't clone arrays returned from getConfigurations()
6862969 javaclasses_2dJPEG JFIF Decoder issue
6862970 javaclasses_2dImage Color Profile parsing issue
6872357 javaclasses_2dJRE AWT setDifflCM vulnerable to Stack Overflow
6872358 javaclasses_2dJRE AWT setBytePixels vulnerable to Heap Overflow
6664512 javaclasses_awtComponent and [Default]KeyboardFocusManager pass security sensitive objects to loggers
6636650 javaclasses_lang(cl) Resurrected ClassLoaders can still have children
6861062 javaclasses_securityDisable MD2 in certificate chain validation
6863503 javaclasses_securitySECURITY: MessageDigest.isEqual introduces timing attack vulnerabilities
6864911 javaclasses_securityASN.1/DER input stream parser needs more work
6854303 javaclasses_soundSun Java HsbParser.getSoundBank Stack Buffer Overflow Vulnerability
6657026 javaclasses_swingNumerous static security flaws in Swing (findbugs)
6657138 javaclasses_swingMutable statics in Windows PL&F (findbugs)
6824265 javaclasses_util_i18n(tz) TimeZone.getTimeZone allows probing local filesystem
6632445 javaimageioDoS from parsing BMPs with UNC ICC links
6862968 javaimageioJPEG Image Writer quantization problem
6874643 javaimageioImageI/O JPEG is vulnerable to Heap Overflow
6869694 javainstalljava update malfunctioning
6869752 java_deploymentdeployment_toolkitDeployment Toolkit plugin "launch" method vulnerable to exploits
6872824 javawebstartgeneralarbitary code execution using java web start
6870531 javawebstartotherREGRESSION:have problem to run JNLP app and applets with signed Jar files

Other bug fixes are listed in the following table.

BugIdCategorySubcategoryDescription
6842999 hotspotruntime_systemUpdate hotspot windows os_win32 for windows 2008 R2
6804454 javaclasses_2dRFE: Provide a way to control the printing dpi resolution from MSIE browser print. See also 6801859
6813208 javaclasses_awtpageDialog throws NPE from applet
6825342 javaclasses_awtSecurity warning may change Z-order of top-level
6843003 javaclasses_langWindows Server 2008 R2 system recognition
6860447 javaclasses_securityAdd GlobalSign R3 Root certificate to the JDK
6872579 javaclasses_securityAdd SECOM Root CA 2 to JDK
6880110 javaclasses_util_i18n(tz) Support tzdata2009m
6814140 javaclasses_util_loggingdeadlock due to synchronized demandLogger() code that locks ServerLogManager
6879614 jaxpparsecom.sun.org.apache.xerces.internal.jaxp.DocumentBuilderImpl failing to parse xml document