Accepted: tomcat6 6.0.18-0ubuntu1 (source)
Thierry Carrez
thierry.carrez at ubuntu.com
Fri Aug 22 15:45:22 BST 2008
Accepted:
OK: tomcat6_6.0.18.orig.tar.gz
OK: tomcat6_6.0.18-0ubuntu1.diff.gz
OK: tomcat6_6.0.18-0ubuntu1.dsc
-> Component: universe Section: web
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Fri, 22 Aug 2008 09:15:11 +0200
Source: tomcat6
Binary: tomcat6-common tomcat6 tomcat6-user libtomcat6-java libservlet2.5-java tomcat6-admin tomcat6-examples tomcat6-docs
Architecture: source
Version: 6.0.18-0ubuntu1
Distribution: intrepid
Urgency: low
Maintainer: Ubuntu MOTU Developers <ubuntu-motu at lists.ubuntu.com>
Changed-By: Thierry Carrez <thierry.carrez at ubuntu.com>
Description:
libservlet2.5-java - Servlet 2.5 and JSP 2.1 Java API classes and documentation
libtomcat6-java - Servlet and JSP engine -- core libraries
tomcat6 - Servlet and JSP engine
tomcat6-admin - Servlet and JSP engine -- admin web applications
tomcat6-common - Servlet and JSP engine -- common files
tomcat6-docs - Servlet and JSP engine -- example web applications
tomcat6-examples - Servlet and JSP engine -- example web applications
tomcat6-user - Servlet and JSP engine -- tools to create user instances
Launchpad-Bugs-Fixed: 256802 256922 256926 260016
Changes:
tomcat6 (6.0.18-0ubuntu1) intrepid; urgency=low
.
* New upstream version (LP: #260016)
- Fixes CVE-2008-2938: Directory traversal vulnerability (LP: #256802)
- Fixes CVE-2008-2370: Information disclosure vulnerability (LP: #256922)
- Fixes CVE-2008-1232: XSS through sendError vulnerability (LP: #256926)
* Dropped CVE-2008-1947.patch (fix is shipped in this upstream release)
* control: Improve short descriptions for the binary packages
* copyright: Added link to /usr/share/common-licenses/Apache-2.0
* control: To pull the right JRE, libtomcat6-java now depends on
default-jre-headless | java6-runtime-headless
Checksums-Sha1:
c7321c8fd58451397f9aed6734f2e284d586b245 1362 tomcat6_6.0.18-0ubuntu1.dsc
9182b0d6b2d0cb2d60f04be6211f3b3516bc518e 3484249 tomcat6_6.0.18.orig.tar.gz
8973d3fbc49c31ece3a2a6062d8883e4a6ad3215 14048 tomcat6_6.0.18-0ubuntu1.diff.gz
Checksums-Sha256:
e68ecc4754b4bce03fd5124a337acb785f602d9da085d3233ab0af61c7e40501 1362 tomcat6_6.0.18-0ubuntu1.dsc
f5ad5dd12e221d75e25234ca734fb434cf45f3fcea93623232a73dc9bfd03dc4 3484249 tomcat6_6.0.18.orig.tar.gz
d02d15c4ba2ac05565944fdc14d18f3598aa57b542da0dba595563c80b360135 14048 tomcat6_6.0.18-0ubuntu1.diff.gz
Files:
8fe770acdfac07071a433e23f51d7ea8 1362 web optional tomcat6_6.0.18-0ubuntu1.dsc
9bdbb1c1d79302c80057a70b18fe6721 3484249 web optional tomcat6_6.0.18.orig.tar.gz
80329d8a8f77a312a706dd19e4371a59 14048 web optional tomcat6_6.0.18-0ubuntu1.diff.gz
Original-Maintainer: Debian Java Maintainers <pkg-java-maintainers at lists.alioth.debian.org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFIrtBBM0thG+z3pVgRAt4JAJ9SvwOGDCkAzq8ah2TBb/EwlzxTDgCgooNF
WpzyUx89zeTJEJcYtJZ8hzI=
=tmt+
-----END PGP SIGNATURE-----
More information about the Intrepid-changes
mailing list