Changelog for
tomcat-javadoc-7.0.92-1.el6.noarch.rpm :
* Thu Dec 13 2018 Coty Sutherland
- 1:7.0.92-1- Update to 7.0.92- Resolves: rhbz#1636513 - CVE-2018-11784 tomcat: Open redirect in default servlet
* Tue Jul 31 2018 Coty Sutherland - 1:7.0.90-1- Update to 7.0.90- Resolves: rhbz#1607586 - CVE-2018-8034 tomcat: host name verification missing in WebSocket client- Resolves: rhbz#1579612 - CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable \'supportsCredentials\' for all origins- Resolves: rhbz#1624929 - CVE-2018-1336 tomcat: A bug in the UTF-8 decoder can lead to DoS
* Tue May 01 2018 Coty Sutherland - 1:7.0.86-1- Update to 7.0.86
* Fri Mar 16 2018 Coty Sutherland - 1:7.0.85-1- Update to 7.0.85- Resolves: rhbz#1548291 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unitended exposure of resources- Resolves: rhbz#1548283 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users
* Thu Feb 01 2018 Coty Sutherland - 0:7.0.84-1- Update to 7.0.84
* Wed Oct 04 2017 Coty Sutherland - 0:7.0.82-1- Update to 7.0.82- Resolves: rhbz#1497681 CVE-2017-12617 tomcat: Remote Code Execution bypass for CVE-2017-12615
* Mon Aug 21 2017 Coty Sutherland - 0:7.0.81-1- Update to 7.0.81- Resolves: rhbz#1480621 CVE-2017-7674 tomcat: Cache Poisoning
* Fri Jun 09 2017 Coty Sutherland - 0:7.0.78-1- Update to 7.0.78- Resolves: rhbz#1459161 CVE-2017-5664 tomcat: Security constrained bypass in error page mechanism
* Tue Apr 11 2017 Coty Sutherland - 0:7.0.77-1- Update to 7.0.77
* Fri Mar 31 2017 Coty Sutherland - 0:7.0.76-1- Update to 7.0.76
* Thu Feb 16 2017 Coty Sutherland - 0:7.0.75-1- Update to 7.0.75- Resolves: rhbz#1420223 CVE-2016-6325 tomcat: tomcat writable config files allow privilege escalation- Resolves: rhbz#1372789 init script status command gives incorrect result
* Tue Nov 29 2016 Coty Sutherland - 0:7.0.73-1- Update to 7.0.73- Resolves: rhbz#1397495 CVE-2016-6816 CVE-2016-8735 tomcat: various flaws
* Fri Sep 23 2016 Coty Sutherland 0:7.0.72-1- Resolves: rhbz#1375582 CVE-2016-5388 Tomcat: CGI sets environmental variable based on user supplied Proxy request header- Resolves: rhbz#1376718 CVE-2016-1240 tomcat: Local privilege escalation via unsafe file handling in the Tomcat init script- Resolves: rhbz#1379170 jsvc script is broken
* Wed Aug 17 2016 Coty Sutherland 0:7.0.70-3- Resolves: rhbz#1170797 remove tomcat6 dependency on redhat-lsb (and any other unnecessary ones)
* Fri Aug 05 2016 Coty Sutherland 0:7.0.70-2- Related: rhbz#1314177 Had to fix a minor syntax issue that caused it to improperly eval
* Fri Aug 05 2016 Coty Sutherland 0:7.0.70-1- Resolves: rhbz#1352120 The javadoc package is useless; it contains one index.html- Resolves: rhbz#1347838 The security manager doesn\'t work correctly (JSPs cannot be compiled)- Resolves: rhbz#1327327 rpm -V tomcat fails on /var/log/tomcat/catalina.out- Resolves: rhbz#1314177 Tomcat init script reports wrong status when one instance of several is stopped- Resolves: rhbz#1312280 Unable to overwrite the TOMCAT_SCRIPT variable- Resolves: rhbz#1104708 Tomcat init script does not respect setting of CATALINA_PID in /etc/sysconfig/tomcat- Resolves: rhbz#1104704 /usr/sbin/tomcat overrides settings specified in /etc/sysconfig/${NAME}- Resolves: rhbz#1364067 The tomcat-tool-wrapper script is broken- Resolves: rhbz#1364068 The command tomcat-digest doesn\'t work- Resolves: rhbz#1311499 Updating package causes tomcat to not start on boot- Resolves: rhbz#1352009 tomcat: multiple security vulnerabilities (updates to 7.0.70)
* Fri Nov 13 2015 Coty Sutherland 0:7.0.65-1- Updated to 7.0.65
* Tue Apr 29 2014 Vlad Slepukhin 0:7.0.33-4- Fixed bug not allowing Tomcat to start properly connected with access privleges to the logging directory- Removed residual systemd configuration from the wrapper
* Wed Feb 26 2014 Vlad Slepukhin 0:7.0.33-3- Changed ExclusiveArch to ExcludeArch due to bug appearing during build with this parameter
* Mon Feb 24 2014 Vlad Slepukhin 0:7.0.33-2- Restrctied to x86_64 and i686 platforms as now requires java 1.6 or later for building and running
* Thu Feb 20 2014 Vlad Slepukhin 0:7.0.33-1- Rebuilded for EL6 compatibility- Removed systemd for compatibility - As no systemd used, systemv moved back to tomcat package- Build now requires ant-trax for compatibility (XSLT and JavaDoc)- Build now requires redhat-lsb for LSB libraries on CentOS- Removed geronimo-jaxrpc as no package found in EL6- Renamed apache-
* packages to jakarta-
* ones for EL6- %add_maven_depmap replaced with install -dm 755 $RPM_BUILD_ROOT//etc/maven/fragmentscat >>$RPM_BUILD_ROOT//etc/maven/fragments/tomcat<< EOF as no such Maven script such EOF- Refactored and cleaned, removing unused code - Removed unused files needed for systemd- Corrected access attributes and rights management for safety purposes
* Sun Nov 03 2013 Ivan Afonichev 0:7.0.47-1- Updated to 7.0.47
* Thu Jul 11 2013 Dmitry Tikhonov 0:7.0.42-1- Updated to 7.0.42
* Sat May 11 2013 Ivan Afonichev 0:7.0.40-1- Updated to 7.0.40- Resolves: rhbz 956569 added missing commons-pool link
* Mon Mar 04 2013 Mikolaj Izdebski - 0:7.0.37-2- Add depmaps for org.eclipse.jetty.orbit- Resolves: rhbz#917626
* Wed Feb 20 2013 Ivan Afonichev 0:7.0.39-1- Updated to 7.0.39
* Wed Feb 20 2013 Ivan Afonichev 0:7.0.37-1- Updated to 7.0.37
* Mon Feb 04 2013 Ivan Afonichev 0:7.0.35-1- Updated to 7.0.35- systemd SuccessExitStatus=143 for proper stop exit code processing
* Mon Dec 24 2012 Ivan Afonichev 0:7.0.34-1- Updated to 7.0.34- ecj >= 4.2.1 now required- Resolves: rhbz 889395 concat classpath correctly; chdir to $CATALINA_HOME
* Fri Dec 07 2012 Ivan Afonichev 0:7.0.33-2- Resolves: rhbz 883806 refix logdir ownership
* Sun Dec 02 2012 Ivan Afonichev 0:7.0.33-1- Updated to 7.0.33- Resolves: rhbz 873620 need chkconfig for update-alternatives
* Wed Oct 17 2012 Ivan Afonichev 0:7.0.32-1- Updated to 7.0.32- Resolves: rhbz 842620 symlinks to taglibs
* Fri Aug 24 2012 Ivan Afonichev 0:7.0.29-1- Updated to 7.0.29- Add pidfile as tmpfile- Use systemd for running as unprivileged user- Resolves: rhbz 847751 upgrade path was broken- Resolves: rhbz 850343 use new systemd-rpm macros
* Sat Jul 21 2012 Fedora Release Engineering - 0:7.0.28-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Mon Jul 02 2012 Ivan Afonichev 0:7.0.28-1- Updated to 7.0.28- Resolves: rhbz 820119 Remove bundled apache-commons-dbcp- Resolves: rhbz 814900 Added tomcat-coyote POM- Resolves: rhbz 810775 Remove systemv stuff from %post scriptlet- Remove redhat-lsb R
* Mon Apr 09 2012 Ivan Afonichev 0:7.0.27-2- Fixed native download hack
* Sat Apr 07 2012 Ivan Afonichev 0:7.0.27-1- Updated to 7.0.27- Fixed jakarta-taglibs-standard BR and R
* Wed Mar 21 2012 Stanislav Ochotnicky - 0:7.0.26-2- Add more depmaps to J2EE apis to help jetty/glassfish updates
* Wed Mar 14 2012 Juan Hernandez 0:7.0.26-2- Added the POM files for tomcat-api and tomcat-util (#803495)
* Wed Feb 22 2012 Ivan Afonichev 0:7.0.26-1- Updated to 7.0.26- Bug 790334: Change ownership of logdir for logrotate
* Thu Feb 16 2012 Krzysztof Daniel 0:7.0.25-4- Bug 790694: Priorities of jsp, servlet and el packages updated.
* Wed Feb 08 2012 Krzysztof Daniel 0:7.0.25-3- Dropped indirect dependecy to tomcat 5
* Sun Jan 22 2012 Ivan Afonichev 0:7.0.25-2- Added hack for maven depmap of tomcat-juli absolute link [ -f ] pass correctly
* Sat Jan 21 2012 Ivan Afonichev 0:7.0.25-1- Updated to 7.0.25- Removed EntityResolver patch (changes already in upstream sources)- Place poms and depmaps in the same package as jars- Added javax.servlet.descriptor to export-package of servlet-api- Move several chkconfig actions and reqs to systemv subpackage- New maven depmaps generation method- Add patch to support java7. (patch sent upstream).- Require java >= 1:1.6.0
* Fri Jan 13 2012 Krzysztof Daniel 0:7.0.23-5- Exported javax.servlet.
* packages in version 3.0 as 2.6 to make servlet-api compatible with Eclipse.
* Thu Jan 12 2012 Ivan Afonichev 0:7.0.23-4- Move jsvc support to subpackage
* Wed Jan 11 2012 Alexander Kurtakov 0:7.0.23-2- Add EntityResolver setter patch to jasper for jetty\'s need. (patch sent upstream).
* Mon Dec 12 2011 Joseph D. Wagner 0:7.0.23-3- Added support to /usr/sbin/tomcat-sysd and /usr/sbin/tomcat for starting tomcat with jsvc, which allows tomcat to perform some privileged operations (e.g. bind to a port < 1024) and then switch identity to a non-privileged user. Must add USE_JSVC=\"true\" to /etc/tomcat/tomcat.conf or /etc/sysconfig/tomcat.
* Mon Nov 28 2011 Ivan Afonichev 0:7.0.23-1- Updated to 7.0.23
* Fri Nov 11 2011 Ivan Afonichev 0:7.0.22-2- Move tomcat-juli.jar to lib package- Drop %update_maven_depmap as in tomcat6- Provide native systemd unit file ported from tomcat6
* Thu Oct 06 2011 Ivan Afonichev 0:7.0.22-1- Updated to 7.0.22
* Mon Oct 03 2011 Rex Dieter - 0:7.0.21-3.1- rebuild (java), rel-eng#4932
* Mon Sep 26 2011 Ivan Afonichev 0:7.0.21-3- Fix basedir mode
* Tue Sep 20 2011 Roland Grunberg 0:7.0.21-2- Add manifests for el-api, jasper-el, jasper, tomcat, and tomcat-juli.
* Thu Sep 08 2011 Ivan Afonichev 0:7.0.21-1- Updated to 7.0.21
* Mon Aug 15 2011 Ivan Afonichev 0:7.0.20-3- Require java = 1:1.6.0
* Mon Aug 15 2011 Ivan Afonichev 0:7.0.20-2- Require java < 1.7.0
* Mon Aug 15 2011 Ivan Afonichev 0:7.0.20-1- Updated to 7.0.20
* Tue Jul 26 2011 Ivan Afonichev 0:7.0.19-1- Updated to 7.0.19
* Tue Jun 21 2011 Ivan Afonichev 0:7.0.16-1- Updated to 7.0.16
* Mon Jun 06 2011 Ivan Afonichev 0:7.0.14-3- Added initial systemd service- Fix some paths
* Sat May 21 2011 Ivan Afonichev 0:7.0.14-2- Fixed http source link- Securify some permissions- Added licenses for el-api and servlet-api- Added dependency on jpackage-utils for the javadoc subpackage
* Sat May 14 2011 Ivan Afonichev 0:7.0.14-1- Updated to 7.0.14
* Thu May 05 2011 Ivan Afonichev 0:7.0.12-4- Provided local paths for libs- Fixed dependencies- Fixed update temp/work cleanup
* Mon May 02 2011 Ivan Afonichev 0:7.0.12-3- Fixed package groups- Fixed some permissions- Fixed some links- Removed old tomcat6 crap
* Thu Apr 28 2011 Ivan Afonichev 0:7.0.12-2- Package now named just tomcat instead of tomcat7- Removed Provides: tomcat-log4j- Switched to apache-commons-
* names instead of jakarta-commons-
* .- Remove the old changelog- BR/R java >= 1:1.6.0 , same for java-devel- Removed old tomcat6 crap
* Wed Apr 27 2011 Ivan Afonichev 0:7.0.12-1- Tomcat7