I’ve released Blackdown’s J2SE 1.4.2-03 for Linux on x86 and AMD64/EM64T yesterday. The release fixes three security issues with the Reflection API (JRE May Allow Untrusted Applet to Elevate Privileges), so make sure you upgrade.
The issue isn’t Blackdown-specific. Sun released an advisory too.
Thanks to Matthias Klose, Debian packages for 1.4.2-03 are available too. Just add something like
deb ftp://ftp.tux.org/java/debian/ sarge non-free
Release files are signed with the Blackdown Java-Linux Package Signing Key. If you have recent
apt version you can use this key to authenticate our Debian packages. Just import the key with
$ wget http://www.blackdown.org/java-linux/java2-status/gpg.asc
$ apt-key add gpg.asc