The updated packages fix several bugs and some security issues:
Font layout engine out of bounds access setCurrGlyphID(). (CVE-2019-2698)
Slow conversion of BigDecimal to long. (CVE-2019-2602)
Incorrect skeleton selection in RMI registry server-side dispatch handling. (CVE-2019-2684)