|
|
|
|
Changelog for tomcat-8.0.39-1.fc23.noarch.rpm :
* Tue Nov 29 2016 Coty Sutherland - 1:8.0.39-1- Update to 8.0.39- Resolves: rhbz#1397493 CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat: various flaws * Tue Oct 25 2016 Coty Sutherland - 1:8.0.38-1- Update to 8.0.38 * Sun Oct 23 2016 Coty Sutherland - 1:8.0.37-3- Resolves: rhbz#1383216 CVE-2016-6325 tomcat: tomcat writable config files allow privilege escalation- Resolves: rhbz#1382310 CVE-2016-5425 tomcat: Local privilege escalation via systemd-tmpfiles service * Tue Sep 13 2016 Coty Sutherland - 1:8.0.37-1- Rebase to 8.0.37- Resolves: rhbz#1375581 CVE-2016-5388 CGI sets environmental variable based on user supplied Proxy request header- Resolves: rhbz#1370262 catalina.out is no longer in use in the main package, but still gets rotated * Thu Aug 11 2016 Coty Sutherland - 1:8.0.36-2- Related: rhbz#1349469 Correct typo in changelog entry * Mon Aug 08 2016 Coty Sutherland - 1:8.0.36-1- Resolves: rhbz#1349469 CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service (updates to 8.0.36)- Resolves: rhbz#1364056 The command tomcat-digest doesn\'t work- Resolves: rhbz#1363884 The tomcat-tool-wrapper script is broken- Resolves: rhbz#1347864 The systemd service unit does not allow tomcat to shut down gracefully- Resolves: rhbz#1347835 The security manager doesn\'t work correctly (JSPs cannot be compiled)- Resolves: rhbz#1341853 rpm -V tomcat fails on /var/log/tomcat/catalina.out- Resolves: rhbz#1341850 tomcat-jsvc.service has TOMCAT_USER value hard-coded- Resolves: rhbz#1359737 Missing maven depmap for the following artifacts: org.apache.tomcat:tomcat-websocket, org.apache.tomcat:tomcat-websocket-api- Resolves: asfbz#59960 Building javadocs with java8 fails * Wed Mar 09 2016 Ivan Afonichev - 1:8.0.32-5- Revert sysconfig migration changes, resolves: rhbz#1311771, rhbz#1311905- Add /etc/tomcat/conf.d/ with shell expansion support, resolves rhbz#1293636 * Sat Feb 27 2016 Ivan Afonichev - 1:8.0.32-4- Load sysconfig from tomcat.conf, resolves: rhbz#1311771, rhbz#1311905- Set default javax.sql.DataSource factory to apache commons one, resolves rhbz#1214381 * Sun Feb 21 2016 Ivan Afonichev - 1:8.0.32-3- Fix symlinks from $CATALINA_HOME/lib perspective, resolves: rhbz#1308685 * Sun Feb 14 2016 Ivan Afonichev - 1:8.0.32-2- Recommend tomcat-native, resolves: rhbz#1243132 * Thu Feb 11 2016 Ivan Afonichev - 1:8.0.32-1- Updated to 8.0.32- Remove log4j support. It has never been working actually. See rhbz#1236297- Move shipped config to /etc/sysconfig/tomcat. /etc/tomcat/tomcat.conf can now be used to override it with shell expansion, resolves rhbz#1293636 * Wed Feb 10 2016 Coty Sutherland 1:8.0.26-3- Resolves: rhbz#1286800 Failed to start component due to wrong allowLinking=\"true\" in context.xml- Program /bin/nologin does not exist (#1302718) * Wed Nov 11 2015 Robert Scheck 1:8.0.26-2- CATALINA_OPTS are only read when SECURITY_MANAGER is true (#1147105) * Thu Aug 27 2015 Alexander Kurtakov 1:8.0.26-1- Update to 8.0.26. * Fri Jul 10 2015 Alexander Kurtakov 1:8.0.24-2- Update to 8.0.24. * Fri Jun 19 2015 Alexander Kurtakov 1:8.0.23-2- Drop javax.el:el-api alias. * Thu Jun 18 2015 Alexander Kurtakov 1:8.0.23-1- Update to 8.0.23. * Thu Jun 18 2015 Alexander Kurtakov 1:8.0.20-3- Drop jetty alias for servlet. * Tue Jun 09 2015 Michal Srb - 1:8.0.20-2- Fix metadata for org.apache.tomcat:{tomcat-jni,tomcat-util-scan} * Thu Mar 05 2015 Alexander Kurtakov 1:8.0.18-5- Rebuild against tomcat-taglibs-standard. * Wed Mar 04 2015 Alexander Kurtakov 1:8.0.18-4- Fix epoch bumped el_1_0_api that would override all other glassfish/jboss/etc. due to wrong epoch.- Drop old provides. * Tue Mar 03 2015 Stephen Gallagher 1:8.0.18-3- Bump epoch to maintain upgrade path from Fedora 22 * Mon Feb 16 2015 Michal Srb - 0:8.0.18-2- Install POM files for org.apache.tomcat:{tomcat-jni,tomcat-util-scan} * Sun Feb 15 2015 Ivan Afonichev 0:8.0.18-1- Updated to 8.0.18 * Sat Sep 20 2014 Ivan Afonichev 0:8.0.12-1- Updated to 8.0.12- Substitute libnames in catalina-tasks.xml, resolves: rhbz#1126439- Use CATALINA_OPTS only on start, resolves: rhbz#1051194 * Mon Jun 16 2014 Michal Srb - 0:7.0.54-3- jsp-api requires el-api * Sun Jun 08 2014 Fedora Release Engineering - 0:7.0.54-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Thu Jun 05 2014 Alexander Kurtakov 0:7.0.54-1- Update to upstream 7.0.54 - fixes compile with Java 8. * Wed May 21 2014 Alexander Kurtakov 0:7.0.52-3- Drop servlet/el api provides to reduce user machines ending with both. * Sun Mar 30 2014 Ivan Afonichev 0:7.0.52-2- Don\'t provide maven javax.jsp:jsp-api and javax.servlet.jsp:javax.servlet.jsp-api resolves: rhbz#1076949- Move log4j support into subpackage, resolves: rhbz#1027716 * Wed Mar 26 2014 Ivan Afonichev 0:7.0.52-1- Updated to 7.0.52- Rewrite jsvc implementation, resolves: rhbz#1051743- Switch to java-headless R, resolves: rhbz#1068566- Create and own /var/lib/tomcats, resolves: rhbz#1026741- Add pom for tomcat-jdbc, resolves: rhbz#1011003 * Tue Jan 21 2014 Mikolaj Izdebski - 0:7.0.47-3- Fix installation of Maven metadata for tomcat-juli.jar- Resolves: rhbz#1033664 * Wed Jan 15 2014 Stanislav Ochotnicky - 0:7.0.47-2- Rebuild for bug #1033664 * Sun Nov 03 2013 Ivan Afonichev 0:7.0.47-1- Updated to 7.0.47- Fix java.security.policy * Sun Aug 04 2013 Fedora Release Engineering - 0:7.0.42-3- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Fri Jul 12 2013 Ivan Afonichev 0:7.0.42-2- Remove jpackage-utils R * Thu Jul 11 2013 Dmitry Tikhonov 0:7.0.42-1- Updated to 7.0.42 * Tue Jun 11 2013 Paul Komkoff 0:7.0.40-3- Dropped systemv inits. Bye-bye.- Updated the systemd wrappers to allow running multiple instances. Added wrapper scripts to do that, ported the original non-named service file to work with the same wrappers, updated /usr/sbin/tomcat to call systemctl. * Sat May 11 2013 Ivan Afonichev 0:7.0.40-1- Updated to 7.0.40- Resolves: rhbz 956569 added missing commons-pool link- Remove ant-nodeps BR * Mon Mar 04 2013 Mikolaj Izdebski - 0:7.0.37-2- Add depmaps for org.eclipse.jetty.orbit- Resolves: rhbz#917626 * Wed Feb 20 2013 Ivan Afonichev 0:7.0.39-1- Updated to 7.0.39 * Wed Feb 20 2013 Ivan Afonichev 0:7.0.37-1- Updated to 7.0.37 * Mon Feb 04 2013 Ivan Afonichev 0:7.0.35-1- Updated to 7.0.35- systemd SuccessExitStatus=143 for proper stop exit code processing * Mon Dec 24 2012 Ivan Afonichev 0:7.0.34-1- Updated to 7.0.34- ecj >= 4.2.1 now required- Resolves: rhbz 889395 concat classpath correctly; chdir to $CATALINA_HOME * Fri Dec 07 2012 Ivan Afonichev 0:7.0.33-2- Resolves: rhbz 883806 refix logdir ownership * Sun Dec 02 2012 Ivan Afonichev 0:7.0.33-1- Updated to 7.0.33- Resolves: rhbz 873620 need chkconfig for update-alternatives * Wed Oct 17 2012 Ivan Afonichev 0:7.0.32-1- Updated to 7.0.32- Resolves: rhbz 842620 symlinks to taglibs * Fri Aug 24 2012 Ivan Afonichev 0:7.0.29-1- Updated to 7.0.29- Add pidfile as tmpfile- Use systemd for running as unprivileged user- Resolves: rhbz 847751 upgrade path was broken- Resolves: rhbz 850343 use new systemd-rpm macros * Sat Jul 21 2012 Fedora Release Engineering - 0:7.0.28-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild * Mon Jul 02 2012 Ivan Afonichev 0:7.0.28-1- Updated to 7.0.28- Resolves: rhbz 820119 Remove bundled apache-commons-dbcp- Resolves: rhbz 814900 Added tomcat-coyote POM- Resolves: rhbz 810775 Remove systemv stuff from %post scriptlet- Remove redhat-lsb R * Mon Apr 09 2012 Ivan Afonichev 0:7.0.27-2- Fixed native download hack * Sat Apr 07 2012 Ivan Afonichev 0:7.0.27-1- Updated to 7.0.27- Fixed jakarta-taglibs-standard BR and R * Wed Mar 21 2012 Stanislav Ochotnicky - 0:7.0.26-2- Add more depmaps to J2EE apis to help jetty/glassfish updates * Wed Mar 14 2012 Juan Hernandez 0:7.0.26-2- Added the POM files for tomcat-api and tomcat-util (#803495) * Wed Feb 22 2012 Ivan Afonichev 0:7.0.26-1- Updated to 7.0.26- Bug 790334: Change ownership of logdir for logrotate * Thu Feb 16 2012 Krzysztof Daniel 0:7.0.25-4- Bug 790694: Priorities of jsp, servlet and el packages updated. * Wed Feb 08 2012 Krzysztof Daniel 0:7.0.25-3- Dropped indirect dependecy to tomcat 5 * Sun Jan 22 2012 Ivan Afonichev 0:7.0.25-2- Added hack for maven depmap of tomcat-juli absolute link [ -f ] pass correctly * Sat Jan 21 2012 Ivan Afonichev 0:7.0.25-1- Updated to 7.0.25- Removed EntityResolver patch (changes already in upstream sources)- Place poms and depmaps in the same package as jars- Added javax.servlet.descriptor to export-package of servlet-api- Move several chkconfig actions and reqs to systemv subpackage- New maven depmaps generation method- Add patch to support java7. (patch sent upstream).- Require java >= 1:1.6.0 * Fri Jan 13 2012 Krzysztof Daniel 0:7.0.23-5- Exported javax.servlet. * packages in version 3.0 as 2.6 to make servlet-api compatible with Eclipse. * Thu Jan 12 2012 Ivan Afonichev 0:7.0.23-4- Move jsvc support to subpackage * Wed Jan 11 2012 Alexander Kurtakov 0:7.0.23-2- Add EntityResolver setter patch to jasper for jetty\'s need. (patch sent upstream). * Mon Dec 12 2011 Joseph D. Wagner 0:7.0.23-3- Added support to /usr/sbin/tomcat-sysd and /usr/sbin/tomcat for starting tomcat with jsvc, which allows tomcat to perform some privileged operations (e.g. bind to a port < 1024) and then switch identity to a non-privileged user. Must add USE_JSVC=\"true\" to /etc/tomcat/tomcat.conf or /etc/sysconfig/tomcat. * Mon Nov 28 2011 Ivan Afonichev 0:7.0.23-1- Updated to 7.0.23 * Fri Nov 11 2011 Ivan Afonichev 0:7.0.22-2- Move tomcat-juli.jar to lib package- Drop %update_maven_depmap as in tomcat6- Provide native systemd unit file ported from tomcat6 * Thu Oct 06 2011 Ivan Afonichev 0:7.0.22-1- Updated to 7.0.22 * Mon Oct 03 2011 Rex Dieter - 0:7.0.21-3.1- rebuild (java), rel-eng#4932 * Mon Sep 26 2011 Ivan Afonichev 0:7.0.21-3- Fix basedir mode * Tue Sep 20 2011 Roland Grunberg 0:7.0.21-2- Add manifests for el-api, jasper-el, jasper, tomcat, and tomcat-juli. * Thu Sep 08 2011 Ivan Afonichev 0:7.0.21-1- Updated to 7.0.21 * Mon Aug 15 2011 Ivan Afonichev 0:7.0.20-3- Require java = 1:1.6.0 * Mon Aug 15 2011 Ivan Afonichev 0:7.0.20-2- Require java < 1.7.0 * Mon Aug 15 2011 Ivan Afonichev 0:7.0.20-1- Updated to 7.0.20 * Tue Jul 26 2011 Ivan Afonichev 0:7.0.19-1- Updated to 7.0.19 * Tue Jun 21 2011 Ivan Afonichev 0:7.0.16-1- Updated to 7.0.16 * Mon Jun 06 2011 Ivan Afonichev 0:7.0.14-3- Added initial systemd service- Fix some paths * Sat May 21 2011 Ivan Afonichev 0:7.0.14-2- Fixed http source link- Securify some permissions- Added licenses for el-api and servlet-api- Added dependency on jpackage-utils for the javadoc subpackage * Sat May 14 2011 Ivan Afonichev 0:7.0.14-1- Updated to 7.0.14 * Thu May 05 2011 Ivan Afonichev 0:7.0.12-4- Provided local paths for libs- Fixed dependencies- Fixed update temp/work cleanup * Mon May 02 2011 Ivan Afonichev 0:7.0.12-3- Fixed package groups- Fixed some permissions- Fixed some links- Removed old tomcat6 crap * Thu Apr 28 2011 Ivan Afonichev 0:7.0.12-2- Package now named just tomcat instead of tomcat7- Removed Provides: tomcat-log4j- Switched to apache-commons- * names instead of jakarta-commons- * .- Remove the old changelog- BR/R java >= 1:1.6.0 , same for java-devel- Removed old tomcat6 crap * Wed Apr 27 2011 Ivan Afonichev 0:7.0.12-1- Tomcat7
|
|
|