[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-22 Thread Luca Falavigna
** Tags added: uus-pre-ff-810 -- Update to Tomcat 6.0.18 https://bugs.launchpad.net/bugs/260016 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/li

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-22 Thread Launchpad Bug Tracker
This bug was fixed in the package tomcat6 - 6.0.18-0ubuntu1 --- tomcat6 (6.0.18-0ubuntu1) intrepid; urgency=low * New upstream version (LP: #260016) - Fixes CVE-2008-2938: Directory traversal vulnerability (LP: #256802) - Fixes CVE-2008-2370: Information disclosure vulnerabi

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-22 Thread Thierry Carrez
Full diff.gz, per request. ** Attachment added: "tomcat6_6.0.18-0ubuntu1.diff.gz" http://launchpadlibrarian.net/17004452/tomcat6_6.0.18-0ubuntu1.diff.gz -- Update to Tomcat 6.0.18 https://bugs.launchpad.net/bugs/260016 You received this bug notification because you are a member of Ubuntu Bugs

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-22 Thread Thierry Carrez
Fixed full interdiff with java6-runtime-headless rather than java5- ** Attachment added: "tomcat6_6.0.18-0ubuntu1.interdiff.gz" http://launchpadlibrarian.net/16995622/tomcat6_6.0.18-0ubuntu1.interdiff.gz ** Changed in: tomcat6 (Ubuntu) Assignee: Thierry Carrez (tcarrez) => (unassigned)

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-21 Thread Thierry Carrez
According to http://tomcat.apache.org/migration.html : "Tomcat 6.0 requires JRE 5.0". This dependency more accurately describes what is needed to run Tomcat. However, on a second thought, Tomcat 6 doesn't run with gij (which provides java5-runtime-headless) so I should probably depend on "default-

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-21 Thread Mathias Gug
Why have you switched from java6-runtime-headless to java5-runtime- headless as the virtual package dependency ? -- Update to Tomcat 6.0.18 https://bugs.launchpad.net/bugs/260016 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-21 Thread Thierry Carrez
New full interdiff for the sponsors. ** Attachment added: "tomcat6_6.0.18-0ubuntu1.interdiff.gz" http://launchpadlibrarian.net/16982792/tomcat6_6.0.18-0ubuntu1.interdiff.gz -- Update to Tomcat 6.0.18 https://bugs.launchpad.net/bugs/260016 You received this bug notification because you are a m

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-21 Thread Thierry Carrez
New consolidated interdiff for simplified review I added a Depends fix, so here are the new files. tomcat6 (6.0.18-0ubuntu1) intrepid; urgency=low * New upstream version (LP: #260016) - Fixes CVE-2008-2938: Directory traversal vulnerability (LP: #256802) - Fixes CVE-2008-2370: Informat

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-21 Thread Thierry Carrez
** Attachment removed: "tomcat6-6.0.18-0ubuntu1.interdiff" http://launchpadlibrarian.net/16981147/tomcat6-6.0.18-0ubuntu1.interdiff ** Attachment removed: "tomcat6_6.0.18-0ubuntu1.interdiff.gz" http://launchpadlibrarian.net/16981138/tomcat6_6.0.18-0ubuntu1.interdiff.gz -- Update to Tomcat 6.0.

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-21 Thread Thierry Carrez
Full interdiff for the sponsors. ** Attachment added: "tomcat6_6.0.18-0ubuntu1.interdiff.gz" http://launchpadlibrarian.net/16981138/tomcat6_6.0.18-0ubuntu1.interdiff.gz ** Changed in: tomcat6 (Ubuntu) Assignee: Thierry Carrez (tcarrez) => (unassigned) Status: In Progress => Confirm

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-21 Thread Thierry Carrez
Consolidated interdiff for simplified review tomcat6 (6.0.18-0ubuntu1) intrepid; urgency=low * New upstream version (LP: #260016) - Fixes CVE-2008-2938: Directory traversal vulnerability (LP: #256802) - Fixes CVE-2008-2370: Information disclosure vulnerability (LP: #256922) - Fixes

[Bug 260016] Re: Update to Tomcat 6.0.18

2008-08-21 Thread Thierry Carrez
** Description changed: Binary package hint: tomcat6 Tomcat 6.0.18 was released on Jul 31 as a security release to fix CVE-2008-1232, CVE-2008-1947, CVE-2008-2370 and CVE-2008-2938. - There was however significant bugfix work for the (doa) 6.0.17 release. - Here is the combined upstrea