please merge tomcat5.5 (5.5.25-5) from Debian unstable (main)

Bug #179491 reported by Matti Lindell
2
Affects Status Importance Assigned to Milestone
tomcat5.5 (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Binary package hint: tomcat5.5

Please consider merging tomcat5.5 from Debian unstable as it contains fixes for two CVE's and also important packaging fixes.

Ubuntu changes that can be dropped:
- Build-depends on xsltproc: tomcat5.5 package used to build documentation using xsltproc, but is now using Xalan-Java (libxalan2-java). I reckon the build dependency was unnecessarily carried around during merges as Debian stopped using it since 5.5.20-2 (related patches were dropped as well). It's not used in build process and the documentation looks the same with or without it. (http://<email address hidden>/msg11269.html and Debian 5.5.20-2 changelog entry).

- Replace the Depends on ecj-bootstrap with ecj: Included in Debian packaging (as libecj-java).

New Debian version also fixes following Ubuntu bugs: bug #153672, bug #159661, bug #161882 and bug #173692.

New Debian changes:

tomcat5.5 (5.5.25-5) unstable; urgency=low

  * debian/tomcat5.5.init: Check if tomcat-users.xml exists.
    Thanks to Javier Serrano Polo for the patch. Closes: #445857.
  * debian/tomcat5.5-webapps.postrm: Purge links created in postinst script.
    Closes: #453879.
  * debian/tomcat5.5-admin.links: Fix symlink for commons-io.jar.
    Closes: #452366.
  * debian/tomcat5.5.init: Check user id of the user running the init script.
    Closes: #457956.
  * Renamed /etc/cron.daily/tomcat5.5 to /etc/cron.daily/tomcat55.
    Closes: #454296.
  * debian/tomcat5.5.init: source /etc/default/locale and export LANG so
    tomcat gets started with system locale. Originally reported to
    https://bugs.launchpad.net/ubuntu/+source/tomcat5.5/+bug/153672.

 -- Michael Koch <email address hidden> Thu, 03 Jan 2008 13:23:44 +0100

tomcat5.5 (5.5.25-4) unstable; urgency=high

  * CVE-2007-5342: Fix unauthorized modification of data because of
    too open permissions. Closes: #458237.
  * Always clean temporary directory on startup. Closes: #456608.

 -- Michael Koch <email address hidden> Sat, 29 Dec 2007 20:15:40 +0100

tomcat5.5 (5.5.25-3) unstable; urgency=low

  * debian/libtomcat5.5-java.links: Removed links for xml-apis.jar and
    xercesImpl.jar. Closes: #443382, #455495.
  * Added libgnumail-java to Build-Depends. Closes: #454312.
  * Updated Standards-Version to 3.7.3.

 -- Michael Koch <email address hidden> Thu, 13 Dec 2007 22:15:18 +0100

tomcat5.5 (5.5.25-2) unstable; urgency=high

  [ Michael Koch ]
  CVE-2007-5461:
  * Fix absolute path traversal vulnerability. Closes: #448664.

  [ Marcus Better ]
  * Add required commons-io symlink to the admin webapp, which fixes WAR
    file uploads. (Closes: #452366)
  * debian/control: Use the new Homepage and Vcs-* fields.
  * debian/NEWS: Remove outdated entry.

 -- Michael Koch <email address hidden> Fri, 30 Nov 2007 10:46:33 +0100

CVE References

Revision history for this message
Matti Lindell (mlind) wrote :
description: updated
description: updated
Revision history for this message
Matti Lindell (mlind) wrote :

Please hold this request until few issues are cleared with Debian maintainers, thanks.

Revision history for this message
Luca Falavigna (dktrkranz) wrote :

Please, resubscribe ubuntu-universe-sponsors when ready, thanks.

Changed in tomcat5.5:
importance: Undecided → Wishlist
Revision history for this message
Matti Lindell (mlind) wrote :

Okay, new Debian version was just release with most of the delta included.

description: updated
Revision history for this message
Mathias Gug (mathiaz) wrote :

Thanks for your debdiff.

I've uploaded your merge.

Could you submit the last delta to Debian ?

Thank you.

Changed in tomcat5.5:
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package tomcat5.5 - 5.5.25-5ubuntu1

---------------
tomcat5.5 (5.5.25-5ubuntu1) hardy; urgency=low

  * Merge from Debian unstable (LP: #153672, LP: #159661, LP: #161882,
    LP: #173692, LP: #179491), remaining changes:
    - debian/control: Change the Maintainer address.
    - debian/rules: Force flag passed to rm to `prune files that should not be
      installed at all'.

tomcat5.5 (5.5.25-5) unstable; urgency=low

  * debian/tomcat5.5.init: Check if tomcat-users.xml exists.
    Thanks to Javier Serrano Polo for the patch. Closes: #445857.
  * debian/tomcat5.5-webapps.postrm: Purge links created in postinst script.
    Closes: #453879.
  * debian/tomcat5.5-admin.links: Fix symlink for commons-io.jar.
    Closes: #452366.
  * debian/tomcat5.5.init: Check user id of the user running the init script.
    Closes: #457956.
  * Renamed /etc/cron.daily/tomcat5.5 to /etc/cron.daily/tomcat55.
    Closes: #454296.
  * debian/tomcat5.5.init: source /etc/default/locale and export LANG so
    tomcat gets started with system locale. Originally reported to
    https://bugs.launchpad.net/ubuntu/+source/tomcat5.5/+bug/153672.

tomcat5.5 (5.5.25-4) unstable; urgency=high

  * CVE-2007-5342: Fix unauthorized modification of data because of
    too open permissions. Closes: #458237.
  * Always clean temporary directory on startup. Closes: #456608.

tomcat5.5 (5.5.25-3) unstable; urgency=low

  * debian/libtomcat5.5-java.links: Removed links for xml-apis.jar and
    xercesImpl.jar. Closes: #443382, #455495.
  * Added libgnumail-java to Build-Depends. Closes: #454312.
  * Updated Standards-Version to 3.7.3.

tomcat5.5 (5.5.25-2) unstable; urgency=high

  [ Michael Koch ]
  CVE-2007-5461:
  * Fix absolute path traversal vulnerability. Closes: #448664.

  [ Marcus Better ]
  * Add required commons-io symlink to the admin webapp, which fixes WAR
    file uploads. (Closes: #452366)
  * debian/control: Use the new Homepage and Vcs-* fields.
  * debian/NEWS: Remove outdated entry.

 -- Matti Lindell <email address hidden> Thu, 03 Jan 2008 20:30:59 +0200

Changed in tomcat5.5:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.