Sync tomcat6 6.0.39-1 (universe) from Debian unstable (main)

Bug #1282923 reported by Gianfranco Costamagna
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tomcat6 (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync tomcat6 6.0.39-1 (universe) from Debian unstable (main)

Changelog entries since current trusty version 6.0.37-1:

tomcat6 (6.0.39-1) unstable; urgency=medium

  * Team upload.
  * New upstream release.
    - Refreshed the patches
  * Standards-Version updated to 3.9.5 (no changes)
  * Switch to debhelper level 9
  * Use XZ compression for the upstream tarball
  * Use canonical URL for the Vcs-Git field

 -- Emmanuel Bourg <email address hidden> Mon, 17 Feb 2014 00:02:00 +0100

CVE References

Revision history for this message
Artur Rona (ari-tczew) wrote :

Thank you for your time and efforts making Ubuntu better! However, we are currently in Feature Freeze, which 6.0.39 seems to be. Please follow the informations on the site https://wiki.ubuntu.com/FeatureFreeze.

I'm unsubscribing Ubuntu Sponsors for now. Please resubscribe when explanation is ready.

Changed in tomcat6 (Ubuntu):
importance: Undecided → Wishlist
status: New → Incomplete
Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :
Download full text (7.0 KiB)

I'm sorry I have missed the Freeze for a couple of days (the package has been pushed in debian in time however).

The rationale is:
-For an LTS something "fresh" should be better indeed.

In the new 2 releases mostly (if not all of them) commits are BUG fix only.
I don't see any new feature in the changelog, while I see one (possibly more) CVE fixed.
For me is better to push, there is many NPE,CVE and other kind of fixes.

Tomcat 6.0.39 (markt)
    Catalina
        fix 55166: Fix regression that broke XML validation when running on some Java 5 JVMs. (kkolinko)
    Coyote
        fix Make the HTTP NIO connector tolerant of whitespace in the individual values used for the ciphers attribute. (markt)
        fix Remove dependency introduced on the jsp-api.jar as part of the XML validation changes introduced in 6.0.38. (markt)
    Jasper
        fix Correct several errors in jspxml Schema and DTD. (kkolinko)
    Cluster
        code Remove an empty TestTwoPhaseCommit test from Tribes. (kkolinko)
    Web applications
        fix Fix broken link in Jasper How-To documentation. (markt)
        fix Align index.html and index.jsp in ROOT web application. Correct links to specifications and to the Tomcat mailing lists. (kkolinko)
        fix Remove second copy of RUNNING.txt from the full-docs distribution. Some unpacking utilities can't handle multiple copies of a file with the same name in a directory. (kkolinko)
    Other
        update Update sample Eclipse IDE project: use JUnit 4 library and prefer a Java 5 JDK when several JDKs are configured. Cleanup the Ant build files. (kkolinko)
        fix Correct Maven dependencies for individual JAR files. (markt)
Tomcat 6.0.38 (markt) not released
    Catalina
        fix Ensure that when Tomcat's anti-resource locking features are used that the temporary copy of the web application and not the original is removed when the web application stops. (markt/kkolinko)
        fix 55019: Fix a potential exception when accessing JSPs while running under a SecurityManager. (jfclere)
        fix 55052: Make JULI's LogManager to additionally look for logging properties without prefixes if the property cannot be found with a prefix. (kkolinko)
        fix 55266: Ensure that the session ID is parsed from the request before any redirect as the session ID may need to be encoded as part of the redirect URL. (markt)
        fix 55404: Log warnings about using security roles in web.xml as warnings. (markt)
        fix 55268: Added optional --service-start-wait-time command-line option to change service start wait time from default of 10 seconds. (schultz)
        fix Correctly associate the default resource bundle with the English locale so that requests that specify an Accept-Language of English ahead of French, Spanish or Japanese get the English messages they asked for. (markt)
        fix Add missing JavaEE 5 XML schema definitions. (markt)
        fix When Catalina parses TLD files, always use a namespace aware parser to be consistent with how Jasper parses TLD files. The tldNamespaceAware attribute of the Context is now ignored. (markt)
        fix As per section SRV.14.4.3 of the Servlet 2.5 specification, a namespa...

Read more...

Changed in tomcat6 (Ubuntu):
status: Incomplete → New
Revision history for this message
Dmitry Shachnev (mitya57) wrote :

I agree that this is a bugfix release, so freeze exception is not needed.

Revision history for this message
Dmitry Shachnev (mitya57) wrote :

This bug was fixed in the package tomcat6 - 6.0.39-1
Sponsored for LocutusOfBorg (costamagnagianfranco)

---------------
tomcat6 (6.0.39-1) unstable; urgency=medium

  * Team upload.
  * New upstream release.
    - Refreshed the patches
  * Standards-Version updated to 3.9.5 (no changes)
  * Switch to debhelper level 9
  * Use XZ compression for the upstream tarball
  * Use canonical URL for the Vcs-Git field

 -- Emmanuel Bourg <email address hidden> Mon, 17 Feb 2014 00:02:00 +0100

Changed in tomcat6 (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.