Changelog for
tomcat6-webapps-6.0.18-20.27.16.noarch.rpm :
Tue Apr 12 14:00:00 2011 mvyskocilAATTsuse.cz
- fix bnc#681914: Expression Language parser whitespace problem
* apache#45511 whitespace problem
* apache#45648 eats the last char in namespace
* add lookaheads to EL pasing
Fri Feb 11 13:00:00 2011 mvyskocilAATTsuse.cz
- fix bnc#669897 - VUL-0: tomcat6: Apache Tomcat Local bypass of security
manger file permissions (CVE-2010-3718)
* http://svn.apache.org/viewvc?view=revision&revision=1022560
- fix bnc#669929 - VUL-0: tomcat6: Apache Tomcat Manager XSS vulnerability
(CVE-2011-0013)
* cherry-picked: http://svn.apache.org/viewvc?view=revision&revision=739524
this closes apache bug#46261
* real fix: http://svn.apache.org/viewvc?view=revision&revision=1057270
- fix bnc#669930 - VUL-0: tomcat6: Apache Tomcat DoS vulnerability
(CVE-2011-0534)
* http://svn.apache.org/viewvc?view=revision&revision=1066313
Mon Jan 17 13:00:00 2011 mvyskocilAATTsuse.cz
- fix bnc#655440#c14 - clean workdir of tomcat6\'s webapps
Thu Nov 25 13:00:00 2010 mvyskocilAATTsuse.cz
- fix bnc#655440 - VUL-0: tomcat6: Apache Tomcat Manager application XSS
vulnerability (CVE-2010-4172)
http://svn.apache.org/viewvc?view=revision&revision=1037779
- fix bnc#653586 - spacewalk 1.2 requires jasper 5.5
* add offline jasper compiler /usr/bin/jspc
Thu Jul 15 14:00:00 2010 mvyskocilAATTsuse.cz
- fix bnc#599554: VUL-1: tomcat information disclosure (CVE-2010-1157)
* http://svn.apache.org/viewvc?view=revision&revision=936540
- fix bnc#622188: VUL-0: tomcat: remote DoS / information disclosure
(CVE-2010-2227)
* http://svn.apache.org/viewvc?view=revision&revision=958977
- link dtomcat6 to CATALINA_HOME/bin/catalina.sh
Thu Feb 4 13:00:00 2010 mvyskocilAATTsuse.cz
- fixed bnc#575083 - VUL-0: tomcat directoy traversal bugs
CVE-2009-2693, CVE-2009-2901, CVE-2009-2902
* http://svn.apache.org/viewvc?view=revision&revision=892815
Wed Jun 10 14:00:00 2009 mvyskocilAATTsuse.cz
- fixed bnc#509839:
CVE-2009-0781
* http://svn.apache.org/viewvc?view=rev&revision=750924
CVE-2009-0783
* http://svn.apache.org/viewvc?view=rev&revision=739522
CVE-2008-5515
* http://svn.apache.org/viewvc?view=rev&revision=739532
Mon Jun 8 14:00:00 2009 mvyskocilAATTsuse.cz
- fixed bnc#509839: CVE-2009-0580
* http://svn.apache.org/viewvc?view=rev&revision=747840
- fixed bnc#509840: CVE-2009-0033
* http://svn.apache.org/viewvc?view=rev&revision=781362
- fixed bnc#485933: cumulative fix for tomcat6:
* bnc#418664 - added /etc/ant.d/catalina-ant
* bnc#424675 - link $CATALINA_BASE/conf/Catalina ->
/var/cache/tomcat6/Catalina/
* bnc#433852 - rctomcat symlink
* bnc#446598 - dtomcat6 reads the tomcat6.conf again, better comment in
config file
Wed Feb 25 13:00:00 2009 mvyskocilAATTsuse.cz
- fixed bnc#471301: tomcat6 doesn\'t want to be started when sun java 1.5 is selected
- built with -target 1.5
Mon Feb 9 13:00:00 2009 mvyskocilAATTsuse.cz
- Fixed bnc#471639 - tomcat does not start/work
- fill up a default JVM in sysconfig