Tue, 26 Nov 2024 01:01:56 UTC | login

Information for build tomcat-9.0.7-1.fc29

ID30619
Package Nametomcat
Version9.0.7
Release1.fc29
Epoch1
SummaryApache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API
DescriptionTomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world.
Built bydavidlt
State complete
Volume DEFAULT
StartedSun, 27 May 2018 22:18:09 UTC
CompletedSun, 27 May 2018 22:18:09 UTC
Tags
f29
RPMs
src
tomcat-9.0.7-1.fc29.src.rpm (info) (download)
noarch
tomcat-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-admin-webapps-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-docs-webapp-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-el-3.0-api-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-javadoc-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-jsp-2.3-api-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-jsvc-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-lib-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-servlet-4.0-api-9.0.7-1.fc29.noarch.rpm (info) (download)
tomcat-webapps-9.0.7-1.fc29.noarch.rpm (info) (download)
Changelog * Tue May 01 2018 Coty Sutherland <csutherl@redhat.com> - 1:9.0.7-1 - Update to 9.0.7 * Thu Mar 15 2018 Coty Sutherland <csutherl@redhat.com> - 1:8.5.29-1 - Update to 8.5.29 - Resolves: rhbz#1548290 CVE-2018-1304 tomcat: Incorrect handling of empty string URL in security constraints can lead to unitended exposure of resources - Resolves: rhbz#1548284 CVE-2018-1305 tomcat: Late application of security constraints can lead to resource exposure for unauthorised users * Fri Feb 09 2018 Igor Gnatenko <ignatenkobrain@fedoraproject.org> - 1:8.0.49-2 - Escape macros in %changelog * Thu Feb 01 2018 Coty Sutherland <csutherl@redhat.com> - 1:8.0.49-1 - Update to 8.0.49 * Tue Dec 12 2017 Merlin Mathesius <mmathesi@redhat.com> - 1:8.0.47-3 - Cleanup spec file conditionals * Tue Oct 24 2017 Troy Dawson <tdawson@redhat.com> - 1:8.0.47-2 - Change "zip -u" to "zip" - Resolves: rhbz#1495241 [tomcat] zip -u in spec file causes race condition * Wed Oct 04 2017 Coty Sutherland <csutherl@redhat.com> - 1:8.0.47-1 - Update to 8.0.47 - Resolves: rhbz#1497682 CVE-2017-12617 tomcat: Remote Code Execution bypass for CVE-2017-12615 * Mon Aug 21 2017 Coty Sutherland <csutherl@redhat.com> - 1:8.0.46-1 - Update to 8.0.46 - Resolves: rhbz#1480620 CVE-2017-7674 tomcat: Cache Poisoning * Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1:8.0.44-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild * Fri Jun 09 2017 Coty Sutherland <csutherl@redhat.com> - 1:8.0.44-1 - Resolves: rhbz#1459160 CVE-2017-5664 tomcat: Security constrained bypass in error page mechanism * Tue Apr 11 2017 Coty Sutherland <csutherl@redhat.com> - 1:8.0.43-1 - Update to 8.0.43 * Fri Mar 31 2017 Coty Sutherland <csutherl@redhat.com> - 1:8.0.42-1 - Update to 8.0.42 * Thu Feb 16 2017 Coty Sutherland <csutherl@redhat.com> - 1:8.0.41-1 - Update to 8.0.41 - Resolves: rhbz#1403825 CVE-2016-8745 tomcat: information disclosure due to incorrect Processor sharing * Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1:8.0.39-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild * Tue Nov 29 2016 Coty Sutherland <csutherl@redhat.com> - 1:8.0.39-1 - Update to 8.0.39 - Resolves: rhbz#1397493 CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat: various flaws * Tue Oct 25 2016 Coty Sutherland <csutherl@redhat.com> - 1:8.0.38-1 - Update to 8.0.38 * Sun Oct 23 2016 Coty Sutherland <csutherl@redhat.com> - 1:8.0.37-3 - Resolves: rhbz#1383216 CVE-2016-6325 tomcat: tomcat writable config files allow privilege escalation - Resolves: rhbz#1382310 CVE-2016-5425 tomcat: Local privilege escalation via systemd-tmpfiles service * Tue Sep 13 2016 Coty Sutherland <csutherl@redhat.com> - 1:8.0.37-1 - Rebase to 8.0.37 - Resolves: rhbz#1375581 CVE-2016-5388 CGI sets environmental variable based on user supplied Proxy request header - Resolves: rhbz#1370262 catalina.out is no longer in use in the main package, but still gets rotated * Thu Aug 11 2016 Coty Sutherland <csutherl@redhat.com> - 1:8.0.36-2 - Related: rhbz#1349469 Correct typo in changelog entry * Mon Aug 08 2016 Coty Sutherland <csutherl@redhat.com> - 1:8.0.36-1 - Resolves: rhbz#1349469 CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service (updates to 8.0.36) - Resolves: rhbz#1364056 The command tomcat-digest doesn't work - Resolves: rhbz#1363884 The tomcat-tool-wrapper script is broken - Resolves: rhbz#1347864 The systemd service unit does not allow tomcat to shut down gracefully - Resolves: rhbz#1347835 The security manager doesn't work correctly (JSPs cannot be compiled) - Resolves: rhbz#1341853 rpm -V tomcat fails on /var/log/tomcat/catalina.out - Resolves: rhbz#1341850 tomcat-jsvc.service has TOMCAT_USER value hard-coded - Resolves: rhbz#1359737 Missing maven depmap for the following artifacts: org.apache.tomcat:tomcat-websocket, org.apache.tomcat:tomcat-websocket-api - Resolves: asfbz#59960 Building javadocs with java8 fails * Wed Mar 02 2016 Ivan Afonichev <ivan.afonichev@gmail.com> - 1:8.0.32-4 - Revert sysconfig migration changes, resolves: rhbz#1311771, rhbz#1311905 - Add /etc/tomcat/conf.d/ with shell expansion support, resolves rhbz#1293636 * Sat Feb 27 2016 Ivan Afonichev <ivan.afonichev@gmail.com> - 1:8.0.32-3 - Load sysconfig from tomcat.conf, resolves: rhbz#1311771, rhbz#1311905 - Set default javax.sql.DataSource factory to apache commons one, resolves rhbz#1214381 * Sun Feb 21 2016 Ivan Afonichev <ivan.afonichev@gmail.com> - 1:8.0.32-2 - Fix symlinks from $CATALINA_HOME/lib perspective, resolves: rhbz#1308685 * Thu Feb 11 2016 Ivan Afonichev <ivan.afonichev@gmail.com> - 1:8.0.32-1 - Updated to 8.0.32 - Remove log4j support. It has never been working actually. See rhbz#1236297 - Move shipped config to /etc/sysconfig/tomcat. /etc/tomcat/tomcat.conf can now be used to override it with shell expansion, resolves rhbz#1293636 - Recommend tomcat-native, resolves: rhbz#1243132 * Wed Feb 10 2016 Coty Sutherland <csutherl@redhat.com> 1:8.0.26-4 - Resolves: rhbz#1286800 Failed to start component due to wrong allowLinking="true" in context.xml - Program /bin/nologin does not exist (#1302718) * Fri Feb 05 2016 Fedora Release Engineering <releng@fedoraproject.org> - 1:8.0.26-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild * Wed Nov 11 2015 Robert Scheck <robert@fedoraproject.org> 1:8.0.26-2 - CATALINA_OPTS are only read when SECURITY_MANAGER is true (#1147105) * Thu Aug 27 2015 Alexander Kurtakov <akurtako@redhat.com> 1:8.0.26-1 - Update to 8.0.26. * Fri Jul 10 2015 Alexander Kurtakov <akurtako@redhat.com> 1:8.0.24-2 - Update to 8.0.24. * Fri Jun 19 2015 Alexander Kurtakov <akurtako@redhat.com> 1:8.0.23-2 - Drop javax.el:el-api alias. * Thu Jun 18 2015 Alexander Kurtakov <akurtako@redhat.com> 1:8.0.23-1 - Update to 8.0.23. * Thu Jun 18 2015 Alexander Kurtakov <akurtako@redhat.com> 1:8.0.20-3 - Drop jetty alias for servlet. * Tue Jun 09 2015 Michal Srb <msrb@redhat.com> - 1:8.0.20-2 - Fix metadata for org.apache.tomcat:{tomcat-jni,tomcat-util-scan} * Thu Mar 05 2015 Alexander Kurtakov <akurtako@redhat.com> 1:8.0.18-5 - Rebuild against tomcat-taglibs-standard. * Wed Mar 04 2015 Alexander Kurtakov <akurtako@redhat.com> 1:8.0.18-4 - Fix epoch bumped el_1_0_api that would override all other glassfish/jboss/etc. due to wrong epoch. - Drop old provides. * Tue Mar 03 2015 Stephen Gallagher <sgallagh@redhat.com> 1:8.0.18-3 - Bump epoch to maintain upgrade path from Fedora 22 * Mon Feb 16 2015 Michal Srb <msrb@redhat.com> - 0:8.0.18-2 - Install POM files for org.apache.tomcat:{tomcat-jni,tomcat-util-scan} * Sun Feb 15 2015 Ivan Afonichev <ivan.afonichev@gmail.com> 0:8.0.18-1 - Updated to 8.0.18 * Sat Sep 20 2014 Ivan Afonichev <ivan.afonichev@gmail.com> 0:8.0.12-1 - Updated to 8.0.12 - Substitute libnames in catalina-tasks.xml, resolves: rhbz#1126439 - Use CATALINA_OPTS only on start, resolves: rhbz#1051194 * Mon Jun 16 2014 Michal Srb <msrb@redhat.com> - 0:7.0.54-3 - jsp-api requires el-api * Sun Jun 08 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:7.0.54-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Thu Jun 05 2014 Alexander Kurtakov <akurtako@redhat.com> 0:7.0.54-1 - Update to upstream 7.0.54 - fixes compile with Java 8. * Wed May 21 2014 Alexander Kurtakov <akurtako@redhat.com> 0:7.0.52-3 - Drop servlet/el api provides to reduce user machines ending with both. * Sun Mar 30 2014 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.52-2 - Don't provide maven javax.jsp:jsp-api and javax.servlet.jsp:javax.servlet.jsp-api resolves: rhbz#1076949 - Move log4j support into subpackage, resolves: rhbz#1027716 * Wed Mar 26 2014 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.52-1 - Updated to 7.0.52 - Rewrite jsvc implementation, resolves: rhbz#1051743 - Switch to java-headless R, resolves: rhbz#1068566 - Create and own %{_localstatedir}/lib/tomcats, resolves: rhbz#1026741 - Add pom for tomcat-jdbc, resolves: rhbz#1011003 * Tue Jan 21 2014 Mikolaj Izdebski <mizdebsk@redhat.com> - 0:7.0.47-3 - Fix installation of Maven metadata for tomcat-juli.jar - Resolves: rhbz#1033664 * Wed Jan 15 2014 Stanislav Ochotnicky <sochotnicky@redhat.com> - 0:7.0.47-2 - Rebuild for bug #1033664 * Sun Nov 03 2013 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.47-1 - Updated to 7.0.47 - Fix java.security.policy * Sun Aug 04 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:7.0.42-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Fri Jul 12 2013 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.42-2 - Remove jpackage-utils R * Thu Jul 11 2013 Dmitry Tikhonov <squall.sama@gmail.com> 0:7.0.42-1 - Updated to 7.0.42 * Tue Jun 11 2013 Paul Komkoff <i@stingr.net> 0:7.0.40-3 - Dropped systemv inits. Bye-bye. - Updated the systemd wrappers to allow running multiple instances. Added wrapper scripts to do that, ported the original non-named service file to work with the same wrappers, updated /usr/sbin/tomcat to call systemctl. * Sat May 11 2013 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.40-1 - Updated to 7.0.40 - Resolves: rhbz 956569 added missing commons-pool link - Remove ant-nodeps BR * Mon Mar 04 2013 Mikolaj Izdebski <mizdebsk@redhat.com> - 0:7.0.37-2 - Add depmaps for org.eclipse.jetty.orbit - Resolves: rhbz#917626 * Wed Feb 20 2013 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.39-1 - Updated to 7.0.39 * Wed Feb 20 2013 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.37-1 - Updated to 7.0.37 * Mon Feb 04 2013 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.35-1 - Updated to 7.0.35 - systemd SuccessExitStatus=143 for proper stop exit code processing * Mon Dec 24 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.34-1 - Updated to 7.0.34 - ecj >= 4.2.1 now required - Resolves: rhbz 889395 concat classpath correctly; chdir to $CATALINA_HOME * Fri Dec 07 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.33-2 - Resolves: rhbz 883806 refix logdir ownership * Sun Dec 02 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.33-1 - Updated to 7.0.33 - Resolves: rhbz 873620 need chkconfig for update-alternatives * Wed Oct 17 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.32-1 - Updated to 7.0.32 - Resolves: rhbz 842620 symlinks to taglibs * Fri Aug 24 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.29-1 - Updated to 7.0.29 - Add pidfile as tmpfile - Use systemd for running as unprivileged user - Resolves: rhbz 847751 upgrade path was broken - Resolves: rhbz 850343 use new systemd-rpm macros * Sat Jul 21 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0:7.0.28-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild * Mon Jul 02 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.28-1 - Updated to 7.0.28 - Resolves: rhbz 820119 Remove bundled apache-commons-dbcp - Resolves: rhbz 814900 Added tomcat-coyote POM - Resolves: rhbz 810775 Remove systemv stuff from %post scriptlet - Remove redhat-lsb R * Mon Apr 09 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.27-2 - Fixed native download hack * Sat Apr 07 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.27-1 - Updated to 7.0.27 - Fixed jakarta-taglibs-standard BR and R * Wed Mar 21 2012 Stanislav Ochotnicky <sochotnicky@redhat.com> - 0:7.0.26-2 - Add more depmaps to J2EE apis to help jetty/glassfish updates * Wed Mar 14 2012 Juan Hernandez <juan.hernandez@redhat.com> 0:7.0.26-2 - Added the POM files for tomcat-api and tomcat-util (#803495) * Wed Feb 22 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.26-1 - Updated to 7.0.26 - Bug 790334: Change ownership of logdir for logrotate * Thu Feb 16 2012 Krzysztof Daniel <kdaniel@redhat.com> 0:7.0.25-4 - Bug 790694: Priorities of jsp, servlet and el packages updated. * Wed Feb 08 2012 Krzysztof Daniel <kdaniel@redhat.com> 0:7.0.25-3 - Dropped indirect dependecy to tomcat 5 * Sun Jan 22 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.25-2 - Added hack for maven depmap of tomcat-juli absolute link [ -f ] pass correctly * Sat Jan 21 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.25-1 - Updated to 7.0.25 - Removed EntityResolver patch (changes already in upstream sources) - Place poms and depmaps in the same package as jars - Added javax.servlet.descriptor to export-package of servlet-api - Move several chkconfig actions and reqs to systemv subpackage - New maven depmaps generation method - Add patch to support java7. (patch sent upstream). - Require java >= 1:1.6.0 * Fri Jan 13 2012 Krzysztof Daniel <kdaniel@redhat.com> 0:7.0.23-5 - Exported javax.servlet.* packages in version 3.0 as 2.6 to make servlet-api compatible with Eclipse. * Thu Jan 12 2012 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.23-4 - Move jsvc support to subpackage * Wed Jan 11 2012 Alexander Kurtakov <akurtako@redhat.com> 0:7.0.23-2 - Add EntityResolver setter patch to jasper for jetty's need. (patch sent upstream). * Mon Dec 12 2011 Joseph D. Wagner <joe@josephdwagner.info> 0:7.0.23-3 - Added support to /usr/sbin/tomcat-sysd and /usr/sbin/tomcat for starting tomcat with jsvc, which allows tomcat to perform some privileged operations (e.g. bind to a port < 1024) and then switch identity to a non-privileged user. Must add USE_JSVC="true" to /etc/tomcat/tomcat.conf or /etc/sysconfig/tomcat. * Mon Nov 28 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.23-1 - Updated to 7.0.23 * Fri Nov 11 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.22-2 - Move tomcat-juli.jar to lib package - Drop %update_maven_depmap as in tomcat6 - Provide native systemd unit file ported from tomcat6 * Thu Oct 06 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.22-1 - Updated to 7.0.22 * Mon Oct 03 2011 Rex Dieter <rdieter@fedoraproject.org> - 0:7.0.21-3.1 - rebuild (java), rel-eng#4932 * Mon Sep 26 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.21-3 - Fix basedir mode * Tue Sep 20 2011 Roland Grunberg <rgrunber@redhat.com> 0:7.0.21-2 - Add manifests for el-api, jasper-el, jasper, tomcat, and tomcat-juli. * Thu Sep 08 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.21-1 - Updated to 7.0.21 * Mon Aug 15 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.20-3 - Require java = 1:1.6.0 * Mon Aug 15 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.20-2 - Require java < 1.7.0 * Mon Aug 15 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.20-1 - Updated to 7.0.20 * Tue Jul 26 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.19-1 - Updated to 7.0.19 * Tue Jun 21 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.16-1 - Updated to 7.0.16 * Mon Jun 06 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.14-3 - Added initial systemd service - Fix some paths * Sat May 21 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.14-2 - Fixed http source link - Securify some permissions - Added licenses for el-api and servlet-api - Added dependency on jpackage-utils for the javadoc subpackage * Sat May 14 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.14-1 - Updated to 7.0.14 * Thu May 05 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.12-4 - Provided local paths for libs - Fixed dependencies - Fixed update temp/work cleanup * Mon May 02 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.12-3 - Fixed package groups - Fixed some permissions - Fixed some links - Removed old tomcat6 crap * Thu Apr 28 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.12-2 - Package now named just tomcat instead of tomcat7 - Removed Provides: %{name}-log4j - Switched to apache-commons-* names instead of jakarta-commons-* . - Remove the old changelog - BR/R java >= 1:1.6.0 , same for java-devel - Removed old tomcat6 crap * Wed Apr 27 2011 Ivan Afonichev <ivan.afonichev@gmail.com> 0:7.0.12-1 - Tomcat7