|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2016-e6651efbaf (tomcat)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 22 Update: tomcat-7.0.68-3.fc22
Date:  Fri, 25 Mar 2016 22:27:03 +0000 (UTC)
Message-ID:  <20160325222703.F16536062BDB@bastion01.phx2.fedoraproject.org>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-e6651efbaf 2016-03-25 18:27:58.250931 -------------------------------------------------------------------------------- Name : tomcat Product : Fedora 22 Version : 7.0.68 Release : 3.fc22 URL : http://tomcat.apache.org/ Summary : Apache Servlet/JSP Engine, RI for Servlet 3.0/JSP 2.2 API Description : Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. -------------------------------------------------------------------------------- Update Information: - Revert sysconfig migration changes, resolves: rhbz#1311771, rhbz#1311905 - Add /etc/tomcat/conf.d/ with shell expansion support, resolves rhbz#1293636 ---- - Load sysconfig from tomcat.conf, resolves: rhbz#1311771, rhbz#1311905 - Set default javax.sql.DataSource factory to apache commons one, resolves rhbz#1214381 ---- - Updated to 7.0.68 - Fix symlinks from $CATALINA_HOME/lib perspective, resolves: rhbz#1308685 - Fix tomcat user shell, resolves rhbz#1302718 - Remove log4j support. It has never been working actually. See rhbz#1236297 - Move shipped config to /etc/sysconfig/tomcat. /etc/tomcat/tomcat.conf can now be used to override it with shell expansion, resolves rhbz#1293636 - Security fix for CVE-2016-0763 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1311093 - CVE-2016-0763 tomcat: security manager bypass via setGlobalContext() https://bugzilla.redhat.com/show_bug.cgi?id=1311093 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update tomcat' at the command line. For more information, refer to "Managing Software with yum", available at https://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds