Branches for Maverick

Name Status Last Modified Last Commit
lp:ubuntu/maverick/tomcat6 bug 2 Mature 2010-08-25 10:16:27 UTC
24. Check for group existence to avoid po...

Author: Thierry Carrez
Revision Date: 2010-08-25 09:07:03 UTC

Check for group existence to avoid postinst failure (LP: #611721)

lp:ubuntu/maverick-proposed/tomcat6 bug 2 Mature 2012-05-04 23:15:30 UTC
28. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2012-01-25 14:09:00 UTC

* SECURITY UPDATE: denial of service via hash collision and incorrect
  handling of large numbers of parameters and parameter values
  (LP: #909828)
  - debian/patches/0019-CVE-2012-0022.patch: refactor parameter handling
    code in conf/web.xml,
    java/org/apache/catalina/connector/Connector.java,
    java/org/apache/catalina/connector/mbeans-descriptors.xml,
    java/org/apache/catalina/connector/Request.java,
    java/org/apache/catalina/filters/FailedRequestFilter.java,
    java/org/apache/catalina/Globals.java,
    java/org/apache/coyote/Request.java,
    java/org/apache/tomcat/util/buf/B2CConverter.java,
    java/org/apache/tomcat/util/buf/ByteChunk.java,
    java/org/apache/tomcat/util/buf/MessageBytes.java,
    java/org/apache/tomcat/util/buf/StringCache.java,
    java/org/apache/tomcat/util/http/LocalStrings.properties,
    java/org/apache/tomcat/util/http/Parameters.java,
    webapps/docs/config/ajp.xml,
    webapps/docs/config/http.xml.
  - CVE-2011-4858
  - CVE-2012-0022

lp:ubuntu/maverick-security/tomcat6 bug 2 Mature 2012-05-04 23:15:28 UTC
28. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2012-01-25 14:09:00 UTC

* SECURITY UPDATE: denial of service via hash collision and incorrect
  handling of large numbers of parameters and parameter values
  (LP: #909828)
  - debian/patches/0019-CVE-2012-0022.patch: refactor parameter handling
    code in conf/web.xml,
    java/org/apache/catalina/connector/Connector.java,
    java/org/apache/catalina/connector/mbeans-descriptors.xml,
    java/org/apache/catalina/connector/Request.java,
    java/org/apache/catalina/filters/FailedRequestFilter.java,
    java/org/apache/catalina/Globals.java,
    java/org/apache/coyote/Request.java,
    java/org/apache/tomcat/util/buf/B2CConverter.java,
    java/org/apache/tomcat/util/buf/ByteChunk.java,
    java/org/apache/tomcat/util/buf/MessageBytes.java,
    java/org/apache/tomcat/util/buf/StringCache.java,
    java/org/apache/tomcat/util/http/LocalStrings.properties,
    java/org/apache/tomcat/util/http/Parameters.java,
    webapps/docs/config/ajp.xml,
    webapps/docs/config/http.xml.
  - CVE-2011-4858
  - CVE-2012-0022

lp:ubuntu/maverick-updates/tomcat6 2 Mature 2012-01-25 14:09:00 UTC
28. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2012-01-25 14:09:00 UTC

* SECURITY UPDATE: denial of service via hash collision and incorrect
  handling of large numbers of parameters and parameter values
  (LP: #909828)
  - debian/patches/0019-CVE-2012-0022.patch: refactor parameter handling
    code in conf/web.xml,
    java/org/apache/catalina/connector/Connector.java,
    java/org/apache/catalina/connector/mbeans-descriptors.xml,
    java/org/apache/catalina/connector/Request.java,
    java/org/apache/catalina/filters/FailedRequestFilter.java,
    java/org/apache/catalina/Globals.java,
    java/org/apache/coyote/Request.java,
    java/org/apache/tomcat/util/buf/B2CConverter.java,
    java/org/apache/tomcat/util/buf/ByteChunk.java,
    java/org/apache/tomcat/util/buf/MessageBytes.java,
    java/org/apache/tomcat/util/buf/StringCache.java,
    java/org/apache/tomcat/util/http/LocalStrings.properties,
    java/org/apache/tomcat/util/http/Parameters.java,
    webapps/docs/config/ajp.xml,
    webapps/docs/config/http.xml.
  - CVE-2011-4858
  - CVE-2012-0022

lp:~james-page/ubuntu/maverick/tomcat6/CVE-2011-3190 bug 1 Development 2011-09-26 10:09:34 UTC
28. * SECURITY UPDATE: Apache Tomcat Auth...

Author: James Page
Revision Date: 2011-09-26 10:07:50 UTC

* SECURITY UPDATE: Apache Tomcat Authentication bypass and information
  disclosure (LP: #843701).
 - d/patches/0015-CVE-2011-3190.patch: Patch from upstream to Prevent AJP
   request forgery via unread request body packet.
 - CVE-2011-3190

lp:~james-page/ubuntu/maverick/tomcat6/fix-654549 bug(Has a merge proposal) 1 Development 2011-04-15 17:32:14 UTC
27. * Fix update failures when JAVA_OPTS ...

Author: James Page
Revision Date: 2011-04-15 17:30:17 UTC

* Fix update failures when JAVA_OPTS contains / (LP: #654549)
  - debian/tomcat6.postinst: amended sed calls to use % instead of / when
    generating /etc/default/tomcat6.

lp:~ubuntu-branches/ubuntu/maverick/tomcat6/maverick-updates-201111081404 (Has a merge proposal) 1 Development 2011-11-08 14:05:40 UTC
27. * Fix update failures when JAVA_OPTS ...

Author: Marc Deslauriers
Revision Date: 2011-04-22 13:35:22 UTC

* Fix update failures when JAVA_OPTS contains / (LP: #654549)
  - debian/tomcat6.postinst: amended sed calls to use % instead of / when
    generating /etc/default/tomcat6.

17 of 7 results