tomcat-8.5.34-1.an3.src
[5.0 MiB] |
Changelog
by JoungKyun.Kim (2018-10-20):
- udpate 8.5.34 (plus repository)
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.34/RELEASE-NOTES
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.33/RELEASE-NOTES
- security issues
. CVE-2018-8014 Low: CORS filter has insecure defaults
. CVE-2018-8034 Low: host name verification missing in WebSocket client
. CVE-2018-8037 Important: Information Disclosure
. CVE-2018-11784 Moderate: Open Redirect
|
tomcat-8.5.32-1.an3.src
[5.0 MiB] |
Changelog
by JoungKyun.Kim (2018-07-28):
- udpate 8.5.32 (plus repository)
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.32/RELEASE-NOTES
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.31/RELEASE-NOTES
- security issues
. CVE-2018-8037 Important: Due to a mishandling of close in NIO/NIO2 connectors
user sessions can get mixed up
. CVE-2018-8034 Low: host name verification missing in WebSocket client
. CVE-2018-8014 Low: CORS filter has insecure defaults
. CVE-2018-1336 Important: A bug in the UTF-8 decoder can lead to DoS
|
tomcat-8.5.30-1.an3.src
[4.9 MiB] |
Changelog
by JoungKyun.Kim (2018-05-02):
- udpate 8.5.30 (plus repository)
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.30/RELEASE-NOTES
|
tomcat-8.5.29-1.an3.src
[4.9 MiB] |
Changelog
by JoungKyun.Kim (2018-04-08):
- udpate 8.5.23 (plus repository)
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.29/RELEASE-NOTES
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.28_(markt)
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.27_(markt)
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.26_(markt)
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.25_(markt)
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.24_(markt)
- security issues
. CVE-2018-1304 Important: Security constraints mapped to context root are ignored
. CVE-2018-1305 Important: Security constraint annotations applied too late
. CVE-2017-15706 Low: Incorrectly documented CGI search algorithm
|
tomcat-8.5.23-1.an3.src
[4.9 MiB] |
Changelog
by JoungKyun.Kim (2017-10-21):
- udpate 8.5.23 (plus repository)
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.23/RELEASE-NOTES
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.23_(markt)
- security issues
. CVE-2017-12617 Important: Remote Code Execution
|
tomcat-8.5.20-1.an3.src
[4.9 MiB] |
Changelog
by JoungKyun.Kim (2017-08-21):
- udpate 8.5.20 (plus repository)
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.20/RELEASE-NOTES
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.20_(markt)
- security issues
. CVE-2017-7675 Important: Security Constraint Bypass
. CVE-2017-7674 Moderate: Cache Poisoning
|
tomcat-8.5.15-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2017-06-13):
- update 8.5.15 (test packaging, don't build binary package)
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.15/RELEASE-NOTES
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.15_(markt)
- security issues
. CVE-2017-5664 Important: Security Constraint Bypass
|
tomcat-8.5.13-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2017-04-12):
- update 8.5.13 (test packaging, don't build binary package)
see also http://apache.mirror.cdnetworks.com/tomcat/tomcat-8/v8.5.13/RELEASE-NOTES
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.13_(markt)
- security issues
. CVE-2017-5651 Important: Information Disclosure
. CVE-2017-5650 Important: Denial of Service
. CVE-2017-5647 Important: Information Disclosure
|
tomcat-8.5.12-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2017-03-22):
- update 8.5.12 (test packaging, don't build binary package)
|
tomcat-8.0.53-1.an3.src
[4.9 MiB] |
Changelog
by JoungKyun.Kim (2018-07-28):
- update 8.0.53
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.52_(markt)
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.53_(markt)
- security issues
. CVE-2018-8034 Low: host name verification missing in WebSocket client
. CVE-2018-8014 Low: CORS filter has insecure defaults
. CVE-2018-1336 Important: A bug in the UTF-8 decoder can lead to DoS
|
tomcat-8.0.51-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2018-05-02):
- update 8.0.51
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.51_(markt)
|
tomcat-8.0.50-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2018-04-08):
- update 8.0.50
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.48_(markt)
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.50_(markt)
- security issues
. CVE-2017-15706 Low: Incorrectly documented CGI search algorithm
. CVE-2018-1304 Important: Security constraints mapped to context root are ignored
|
tomcat-8.0.47-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2017-10-21):
- update 8.0.47
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.47_(markt)
- security issues
. CVE-2017-12617 Important: Remote Code Execution
|
tomcat-8.0.46-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2017-08-21):
- update 8.0.46
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.45_(markt)
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.46_(markt)
- security issues
. CVE-2017-7674 Moderate: Cache Poisoning
|
tomcat-8.0.44-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2017-06-13):
- update 8.0.44
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.44_(markt)
- security issues
. CVE-2017-5664 Important: Security Constraint Bypass
|
tomcat-8.0.43-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2017-04-12):
- update 8.0.42
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.43_(markt)
- security issues
. CVE-2017-5647 Important: Information Disclosure
|
tomcat-8.0.42-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2017-03-21):
- update 8.0.42
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.42_(markt)
http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.41_(markt)
http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.40_(markt)
http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.39_(markt)
http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.38_(markt)
- security issues
. CVE-2016-8735 Important: Remote Code Execution
. CVE-2016-6816 Important: Information Disclosure
. CVE-2016-8745 Important: Information Disclosure
|
tomcat-8.0.37-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2016-09-16):
- update 8.0.37
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.37_(markt)
- security issues
. CVE-2016-3092
The MultipartStream class in Apache Commons Fileupload allows remote
attackers to cause a denial of service (CPU consumption) via a long
boundary string.
|
tomcat-8.0.33-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2016-04-23):
- update 8.0.33
see also http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.33_(markt)
|
tomcat-8.0.32-1.an3.src
[4.8 MiB] |
Changelog
by JoungKyun.Kim (2016-02-22):
- replace java dependency to java-headless
- exclude tomcat-taglibs-standard
|