lp://staging/ubuntu/natty-proposed/tomcat6
- Get this branch:
- bzr branch lp://staging/ubuntu/natty-proposed/tomcat6
Branch merges
Branch information
Recent revisions
- 36. By Marc Deslauriers
-
* SECURITY UPDATE: denial of service via hash collision and incorrect
handling of large numbers of parameters and parameter values
(LP: #909828)
- debian/patches/ 0019-CVE- 2012-0022. patch: refactor parameter handling
code in conf/web.xml,
java/org/apache/ catalina/ connector/ Connector. java,
java/org/apache/ catalina/ connector/ mbeans- descriptors. xml,
java/org/apache/ catalina/ connector/ Request. java,
java/org/apache/ catalina/ filters/ FailedRequestFi lter.java,
java/org/apache/ catalina/ Globals. java,
java/org/apache/ coyote/ Request. java,
java/org/apache/ tomcat/ util/buf/ B2CConverter. java,
java/org/apache/ tomcat/ util/buf/ ByteChunk. java,
java/org/apache/ tomcat/ util/buf/ MessageBytes. java,
java/org/apache/ tomcat/ util/buf/ StringCache. java,
java/org/apache/ tomcat/ util/http/ LocalStrings. properties,
java/org/apache/ tomcat/ util/http/ Parameters. java,
webapps/docs/config/ ajp.xml,
webapps/docs/config/ http.xml.
- CVE-2011-4858
- CVE-2012-0022 - 35. By Marc Deslauriers
-
* SECURITY UPDATE: information disclosure via log file
- debian/patches/ 0015-CVE- 2011-2204. patch: fix logging in
java/org/apache/ catalina/ mbeans/ MemoryUserDatab aseMBean. java,
java/org/apache/ catalina/ users/MemoryUse rDatabase. java,
java/org/apache/ catalina/ users/MemoryUse r.java.
- CVE-2011-2204
* SECURITY UPDATE: file restriction bypass or denial of service via
untrusted web application.
- debian/patches/ 0016-CVE- 2011-2526. patch: check canonical name in
java/org/apache/ catalina/ connector/ LocalStrings. properties,
java/org/apache/ catalina/ connector/ Request. java,
java/org/apache/ catalina/ servlets/ DefaultServlet. java,
java/org/apache/ coyote/ http11/ Http11AprProces sor.java,
java/org/apache/ coyote/ http11/ LocalStrings. properties,
java/org/apache/ tomcat/ util/net/ AprEndpoint. java,
java/org/apache/ tomcat/ util/net/ NioEndpoint. java.
- CVE-2011-2526
* SECURITY UPDATE: AJP request spoofing and authentication bypass
(LP: #843701)
- debian/patches/ 0017-CVE- 2011-3190. patch: Properly handle request
bodies in java/org/apache/ coyote/ ajp/AjpAprProce ssor.java,
java/org/apache/ coyote/ ajp/AjpProcesso r.java.
- CVE-2011-3190
* SECURITY UPDATE: HTTP DIGEST authentication weaknesses
- debian/patches/ 0018-CVE- 2011-1184. patch: add new nonce options in
java/org/apache/ catalina/ authenticator/ DigestAuthentic ator.java,
java/org/apache/ catalina/ authenticator/ LocalStrings. properties,
java/org/apache/ catalina/ authenticator/ mbeans- descriptors. xml,
java/org/apache/ catalina/ realm/RealmBase .java,
webapps/docs/config/ valve.xml.
- CVE-2011-1184 - 34. By Abhinav Upadhyay
-
debian/
tomcat6- instance- create: Eclipse can now be configured to use a user instance
of tomcat6 using tomcat6-instance- create without any additional work.
tomcat6-instance- create will setup all the necessary symlinks to make eclipse work.
(Closes: #551091) (LP: #297675) - 33. By Abhinav Upadhyay
-
[ Abhinav Upadhyay ]
* tomcat6-instance- create should accept -1 as the value of -c option
as per http://tomcat. apache. org/tomcat- 6.0-doc/ config/ server. html
(LP: #707405)
[ Dave Walker (Daviey) ]
* debian/control: Updated Maintainer as per policy. - 32. By Tony Mancill
-
* Team upload.
* Add Portuguese/Brazilian debconf translation.
Thanks to José de Figueiredo (Closes: #608527)
* Add patches for CVE-2011-0534, CVE-2010-3718, CVE-2011-0013
(Closes: #612257) - 31. By Tony Mancill
-
* Team upload.
* Update URL for manager application in README.Debian
Thanks to Ernesto Ongaro (Closes: #606170)
* Add patch for CVE-2010-4172. (Closes: #606388) - 30. By Tony Mancill
-
* Team upload.
[ Thierry Carrez (ttx) ]
* Do not fail to purge if /etc/tomcat6 was manually removed (LP: #648619)
* Add missing -p option in start-stop-daemon when starting tomcat6 to avoid
failing to start due to /bin/bash running (LP: #632554)
* Fix build failure (missing TraXLiaison class) by adding ant-nodeps
to the classpath.[ tony mancill ]
* Use debconf to determine tomcat6 user and group to delete upon purge.
Thanks to Misha Koshelev. (Closes: #599458)
* Add tomcat-native to Suggests: for tomcat6 binary package.
Thanks to Eddy Petrisor (Closes: #600590)
* Add Danish debconf template translation.
Thanks to Joe Dalton (Closes: #605070)
* Actually add the Czech debconf template translation.
Thanks this time to Christian PERRIER (Closes: #597863) - 29. By Thierry Carrez
-
debian/control: Reapply ant1.7-optional to ant-optional change, was
accidentally reverted in last upload. - 28. By Thierry Carrez
-
debian/
tomcat6. init: Add missing -p option in start-stop-daemon when
starting tomcat6 to avoid failing to start due to /bin/bash running
(LP: #632554) - 27. By James Page
-
* Build-depend on ant/ant-optional (1.8.1)
* Amended debian/rules, fix xslt processing in ant 1.8.1 to
fix FTBFS (LP: #662588)
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp://staging/ubuntu/quantal/tomcat6