#53246 closed update (fixed)
tomcat6 @6.0.35_1: update to 6.0.53
Reported by: | l2dy (Zero King) | Owned by: | blair (Blair Zajac) |
---|---|---|---|
Priority: | Normal | Milestone: | |
Component: | ports | Version: | |
Keywords: | security | Cc: | blair (Blair Zajac) |
Port: | tomcat6 |
Description
http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.49
Tomcat 6.0.48 and 6.0.49 fixed three important vulnerabilities.
Change History (7)
comment:1 Changed 8 years ago by l2dy (Zero King)
comment:2 Changed 7 years ago by l2dy (Zero King)
Keywords: | security added |
---|---|
Resolution: | → wontfix |
Status: | new → closed |
Summary: | tomcat6 @6.0.35_1: update to 6.0.49 [security] → tomcat6 @6.0.35_1: update to 6.0.53 |
Tomcat 6 distfiles are not available on apache mirrors any more.
Edit: still available on https://archive.apache.org/dist/tomcat/tomcat-6/v6.0.53/, leave closed due to EOL.
comment:3 Changed 7 years ago by blair (Blair Zajac)
Owner: | set to blair |
---|---|
Resolution: | wontfix → fixed |
comment:4 follow-up: 5 Changed 7 years ago by blair (Blair Zajac)
It seems wrong to leave a version with a known security issue in MacPorts since MacPorts is always live. It's not like Ubuntu 12.04 or some version which is retired, so I updated it.
comment:5 Changed 7 years ago by l2dy (Zero King)
Replying to blair:
It seems wrong to leave a version with a known security issue in MacPorts since MacPorts is always live. It's not like Ubuntu 12.04 or some version which is retired, so I updated it.
I planned to create a ticket for removing the port, I dislike keeping unsupported old releases of an active project in our tree.
Your update didn't build on our Buildbot, did you test it?
comment:6 Changed 7 years ago by blair (Blair Zajac)
My bad, no, I didn't try to compile it until now.
I cannot get the commons-collections dependency to compile using Java 8, so maybe we should just delete all these.
Also, compiling our own Java packages seems backwards now instead of using precompiled ones.
comment:7 Changed 7 years ago by l2dy (Zero King)
Dependency commons-daemon also failed to build and is outdated, see #36522.
Note that Tomcat 6.0.49 is not yet released.