Created by James Westby and last modified
Get this branch:
bzr branch lp:debian/axis
Members of Ubuntu branches can upload to this branch. Log in for directions.

Related bugs

Related blueprints

Branch information

Ubuntu branches

Recent revisions

19. By Emmanuel Bourg on 2014-10-17

* Updated the dependency on the Servlet API (3.0 -> 3.1)
* libaxis-java no longer depends on the Servlet API since it's always
  provided by the web container executing Axis.
* Replaced the dependency on libgnumail-java with libmail-java

18. By Markus Koschany on 2014-09-25

* Team upload.
* Fix CVE-2014-3596.
  - Replace 06-fix-CVE-2012-5784.patch with CVE-2014-3596.patch which fixes
    both CVE issues. Thanks to Raphael Hertzog for the report.
  - The getCN function in Apache Axis 1.4 and earlier does not properly
    verify that the server hostname matches a domain name in the subject's
    Common Name (CN) or subjectAltName field of the X.509 certificate,
    which allows man-in-the-middle attackers to spoof SSL servers via a
    certificate with a subject that specifies a common name in a field
    that is not the CN field. NOTE: this issue exists because of an
    incomplete fix for CVE-2012-5784.
  - (Closes: #762444)
* Declare compliance with Debian Policy 3.9.6.
* Use compat level 9 and require debhelper >=9.
* Use canonical VCS fields.

17. By Emmanuel Bourg on 2013-05-15

* Updated the dependency on the Servlet API (2.5 -> 3.0)
* Removed the obsolete dependency on the Activation Framework (libgnujaf-java)
* Added the upstream changelog
* debian/rules: Improved the clean target to allow rebuilds

16. By Tony Mancill on 2013-05-13

* Team upload.
* Upload to unstable.

15. By Alberto Fernández on 2012-12-06

* Non-maintainer upload.
* Fix CVE-2012-5784 (Closes: #692650)
* Fix CN extraction from DN of X500 principal.
* Fix wildcard validation on ssl connections

14. By Alberto Fernández on 2012-12-05

* Non-maintainer upload.
* Fix CVE-2012-5784 (Closes: #692650)

13. By Jakub Adam on 2011-10-31

* Add missing dependency on libcommons-httpclient-java
* Update Export-Package OSGi attribute in manifest
* Add Require-Bundle OSGi attributes

12. By Jakub Adam on 2011-10-27

* Add OSGi metadata to jar manifests
* Bump to Standards-Version 3.9.2
* Updated the DEP-5 copyright to r202

11. By Torsten Werner on 2011-09-08

* Team upload.
* Drop package libaxis-java-gcj.

10. By Damien Raude-Morvan on 2011-03-06

[ tony mancill ]
* libaxis-java-gcj: Remove incorrect libservlet2.4 depedency;
  the dependency on libaxis-java is sufficient.
  Thanks to Matthias Klose. (Closes: #597950)

[ Damien Raude-Morvan ]
* d/control: Bump Standards-Versions to 3.9.1 (no changes required).
* d/control: Change short synopsis of packages.
* Finaly upload to unstable.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
This branch contains Public information 
Everyone can see this information.