tomcat6-docs-webapp-0:6.0.24-115.el6_10$>4 m}_vmհ5>8?d( , W (0 4 8 @ # $D&L(,d,.../#(/S8/\y91@y:FyG|,H~4I<XY\]^3bdefltu$v, wxCtomcat6-docs-webapp6.0.24115.el6_10The docs web application for Apache TomcatThe docs web application for Apache Tomcat.^x86-01.bsys.centos.org&vCentOSASL 2.0CentOS BuildSystem System Environment/Applicationshttp://tomcat.apache.org/linuxnoarch!WA\8c]A\H$ *utNqa ) |~Fx _&,6SM@2*226v!>?ElOΏV&w>n^cF QWyg?e@p6Z95S2h o`Yks+1&YN(ZLO,67wvj.i;҉ XM 6; [A큤A큤A큤A큤A큤A큤AA큤AA큤A큤A큤A큤A큤A큤A큤A큤A큤^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^500bba1d715bf5fe335639d668f6bfee18ce8686db7fc8e7b0d94067831fea990541d7af452e478e280a60186be04c5c0da6b5937aa1f16b2da2b783f73ef9b329babd71558697eb69ae24df337dc58686d5bc9d2ffbf4a8ce18db8714228301b07a199a14a8337e93c708b1409ded652e4eeea5e3477a4713487be79ae7dc0d5cd09f4adf47f5bed64f1b06e06a039baf1a34ff1806db0011a7bf1736b50f8584918a2f6e84cf2a18c72c8c2c9572b19c3f2d301ec28a1252531c4164b795312239db9f177a2c0751687b2704fb7156753b96e89310657e42d0e93e86d2f53983ea0770ce89ffc83977d194ab60c100bf724cf60a83eebee0436fdc0ff3682f568e20cbe141de1c8deb62e792cba2873011cc68c8119ac0a16d2f6a867027d62c109d275a3c91b68202e6b56b09a1a58f02be24127c98467352f07ac3d65f0b6e265f0943d84d90e4700c7546370ea683332c1e87f8601fcbd1c8a7ffeea38a95fdf1b294a3c99af6431530eb9cb5b03efb0eed82135498429f2638f3458cb82239db9f177a2c0751687b2704fb7156753b96e89310657e42d0e93e86d2f53977f84b68ac01984d8566203b324eae905f1883f5dcffd6d8c7a6342a765474582342566a1513d459155fbe00ec7b6e315ce339f2422a2e5ab2ea09194e70e140b057d2f2726dbfded4c11a167f69adb6d1a1435742a8660f2b9548ffb0123d69361ea8e038952c98490c9a9e2b7ad6bf8de266caea7b43eae2a7592a5d7021d78492e50c3d1efafa40414a687eca7feeb9916e68897ab396a58d8383cca8679fc8ecc0090fc2950d97ebc4102675b21904838f64e253702d520ac3819944bfc2d5a913ca95349413b88a45407c70c97b1166bd7aae16d88675e5f10c53c3be766a7ae32a422ccb1575bd2f4bbfcf16fcde1351f9890c40eb4ee4ccd53e812f2e608b7b9478f7b5306f66e00c60a3567cf3011daf72a1dcf0ffe1d9723ab77cc4f41f0d958d98e200c8139ff7e0e35dad6d063804d1482967222c1f6b1acae8744decc00bb3b97d09ff7581bddf6388bf3dc8d8bc37998d1d1202323ec31e2241410c740adcc63d3626ec97c23b38524acd56d87e2c50d5fe4e16718aa533d469f942db5e3d33871fb2233a00cead9ba7a636f3b1ee104a02df5fc1c71836e8e5cbe1c3186c3e5a9e7e44eaeeb81de609b7426ab8c975ea65d829be888f9e17d3992b8bcc73b9675ae023540c2603e7d49ee9c9693e4bb6431cdcaa30540a0d0186a8e600af53317de1cc1abcc587ec77f7ba2f001f3b87a4e2545d14d28e4300ba2f4c6806ed4a3e2ca487b25b66d6cdb3f7869a9c724950c2c8a8b9ed1e2b033b2c53e657181de37ca981a784b75fecd12215a41960778d27e6d32ab54bbdd612e40fdede171f5857066e7dc477d310c8071e01bfb3862a6357a570894344a4c3c0dcd38cb5d3bf246822cec134e34d7cb903370f12c1787582f652cbc37ead9e979de0626889cf3cf01d6d3001d91971ba6de681fba188a701bf577a88cb8acd2480a1cb5a929747a505b38460d7aaf3ea89fbffd4ada759723525db4bc90112f575562c2bb73c419e1038e9acc978437735066904abd5bd8528f1bdf223c487dc28112ce05e44a47b4138eccdd218f1b7066370c092ee78dceefd473fa38d2d4122c146fee99e4aea6a72883d01d5e5cdb64463e1507eef8a71075ffa25464f4d5bee3b517f6f352db383039db188b83856e35e459f36a0a16013b8adc7f6147397b37040d19e96cebd00a8fc10f1439ea75fedd76039f907eb35f5782064861a47a6a10b833b1de00afb75b0b993fe316532a8e98e3d71defa093ce2425cbbee168d3b37831781cd25ef6a55ffe7a6db13e88083cc7f93a48e319625bb27668bc6613e6340af2e85597f4f7541c8603ebf4b44fad235e4f4041e98b44d26b791f477b783ee603b1243254479e97788948b829b073c302b7f6f8c4fc48c75a18745f28a5c983613c45aa64af9a7b72348af64b54d222444bb42ed3d64d83bedfcae7a5168300e12dc09c726d9cc4572a329976035ee4238f87882f2511d34cc759fbd0569ff2c59e469b5aaf4e42c5b4445e600feab2d077abee772e07258dcdf85aa4618db118c10f660188a8326335830c82723fc5be863f23f854d0a807a947ea83ab0eafe1543ae5671e812756c18eeec6a6ff02d0a8ee2b44486835cd1d508856edf927e0f834980df6b6a66ceb5e62486b80d612bf67df20285fb54e048906f97c33936dc0d50e100f4f6d7bdc8d10aa1d208eb893d76760d45a0d4bb404478ad0decd641c35f229505f11f7b4ed2e30016a7648e7fcf2b0de01cea415422fafac0294fa885c85c6d443efcc1d369ce207797467fdbc3e3f5c6db13be579c961c17d3f1502e39c46bd637428f6fe7e032cf8fc0f02b4babe1e40b9563e4fd16f4a28858088c754142e5b330beae782187d3235b700bc973688f90425816087c6bdabf8d9c006053c5ead05e356c862244c719d5667b79533cb114ead2b0cc9c5471cd8619791ec776ceb8d2896ed38fa311f40dd6df2fc0dac41089b3067038e415ab8e62ae5a6a72d45f24c787a1e73aa167af8edcea1a7e7066f8abe8237db85accba32de07d5d8c282f822e8d6c61298faa15ee1bdddda1808485f34d1d2a92020a7414c4cc32a2dc7cc9ac947852a6f353ace1852d6f9778748aa7df22f73324e39b09815a772cf270237b81695ec2505e82101294137c5d79c22cdd40728435bd82785a7a252b9dea3c9a4f374b86feb4ba399e16d63bd16e0abe5a6cee334d75e29fae79be2ca6e8fd58a532ee00add158e256896fb724d54f4e9c856d33b1cf37cb7146ec549863002e975380284b607abf810ee1dad6321d2c5c1da4b286e32a735c0eb0ad481684db70b6210f2423b64ba416d1f9823106ec1e15ee4450b9ee60de517d63f38e3273e52ebd59aec11a7409361418f5736dca497755d0b6b2f0679a861fef935ab812544fe56b7c9f5dd3741b699f94747dff10523b243496334a2bd69750f3b087ad6187ca240eca06d2c7664eaada464e5b5c4450e8a6a81224d0168883a02addc00e5ac17b5e5c0e7864a32c144c26dd317908f670a850562899f86f728a582991ce03ce46003b7203939068e2615e13ba4752e67269d2ca63e2d8d572d36003fc3eb350c99b90fe49cc6fe619a4bfdcc48c79c8ea70a9051322488a30d24bcd3d98d49c14171b955de832abcd3029b48da5cb76d094259cb0ba6e86fd8ff34b3d6622552b09ca48f9ebb60cb1758ffd80e640a415fa775ccd100cc31662f0ae961868f192e26e7954a7c97caac157fd2d4f6344e15ed07c7f681e90a4e7eb5e229f3a300b34ccf8260f1918a62d3378591ba23c2d04f2d027b9044b33b8570c40d15f96df096f2c8823e8cac8e34ae52261043ee0953e9c42a0e74b1747ce36f4abcd12af9c4c40955ae58ccb3656754dcffbc62512e3ab55351266e77cb8ccc6511fcd940fc4376d447524d77f365883f15dd80292531e2ebbad229b12a147da9c1006769aa2bb0e1896b3393982b31187fa7e1afc4f8b90cb3b0cbea1adf338c31bc0128013999e86a6c8defa665d52112c36fa422d381aec5ffb57c31912b60ca0e47b56634beaae1a4eb8c826f5bf5a1d54a67660ee1671db4e8ebf2dfaaba444a572b90d7edc826e22fd1d6a2cac0dba2ac0d6abdb2d037f07499a84df7f9a949e5e76a4d89dd3913b96e3ec60410d16b47d3901eee99d0090e19fdb28ab78e3fff49f571c5ece6cca5eaa4ca83e056ba73609403a3ef0ac82395a4fccae251ecef1878c569a3a5ee2f4e94f2b56e19054224482be0aa7b444ab8324ed0b0c25e3abacbd87be29732356c9bb8e3aaa2cb9c451791e47550904c4a3426f15c3629ee5f516410a616b0a1ba61606cfcc73a8006d99892a7e123777217014ec48ff0085bae3654aa66f1b6838e3bbfbac438f3c7acdbb046661e33e3e10dc80f93486f1e7a10689b4ea4e616342963b93e248018e9520b508c50c9f61fb190bb7ed7c057598111baf79d07c3ad14afe0dcfca292a0fae8bce08a48c14d3e59c9d82c6052ab6d48a22ecc6c48f277c53a5ef07d7c48a567b33ffb6b8f46f7cb60d0e80c09868c193a9e7f43bd5dcfd3cd3af4b77ad85eca96510e7187215e9bd98b82a985ac73011ce821f6e994457c62b1f21525a9c965d21eeaa2a89b7706a1cb0833a83f27b16916b04f45c3d8135e6e894ba2988ae9f3f21c424e7536d091c29cae6c3d63d9b700f6ee914e6a3ebc1ad7e2a34c58b767609c1ed16f51821eafc588508384ff4a66c1d09a639cfe607ac1b5eb7eef350bc0aa6469ed58023f811a55d4945c7bd203c159d023bd901e4a36bef86f6082fe4b233329d6a9689ec7c015a48686ec62053c0873b7582e5483877d0ee1c46bc2d9a026828267322de362e3c9c84bbdfee4d93ed084ecdaf03322da5075e1c65cde89cb7b81b99a89e4136c60e87ae4c9a97897f3a442571b9fc77031a73eda4f5cbfb85f59f1863e14d5170d3ab46d5baba5f575e6954afd73bc03b5d582a710abe6f4979473a460be6df58af8d4add0ad0c8222c241ff75da56c3a899eb89f1208c80a24fded277b9e61d706518f82b3c8140f85bcd624c346d4fcf123ad8c4e7e79bfd68ecee2d53c80b89b1da820efe3c23cca67eac253e1500f8e418fd44b35923ea2456b98e37222ac0db4c32a633cea73733812397f19406780ac9164845cc65816f45abe0598820af609cf86715ec3da7960ea6fe3fa4ad3f62c329aed6835f4bfc78426d0989818ec394c6da747ae18c0d0649e82396df99d691c011d662dc5768f1ef85c0f6e343e7393496c268a6a8e8cac92a80241ef40a89375d0780a65b2c2d2e6fcb5274194081d7b219fbc9f6b8b1a81dbabf3c6172bbb3d1fa44b1577d4cf47ba3e0602c5e8b4e4716cc7daaa062c24901ccda273d2199f60408fa80a830d90b94ff949221795e23d294c599168df6f3d9a4b7226b1bdb7251ec9e1d1d3076873c83fa35f62bdca6433800c8530erootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootroottomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcattomcat6-6.0.24-115.el6_10.src.rpmtomcat6-docs-webapp    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)tomcat6rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-10:6.0.24-115.el6_105.2-14.8.0^ϧ^oj@^g@^b;@ZN@X@XX@W:WW@V@VVwVwVn@Vn@Vii@VhV2 @UUUUUT@T@T@T@T@T@TfT&@T@TS/SS@S"@S @SB@R0[@R/ R(r@R%@RC@R6Q@Q@Q@Q@P@P @PPj@OOtNO_6OOdOKONNi@N[@M@MMVMVMVM'M@M>MM~@MwkMp@M] M] MQ0@Ls@LL*@Le3LYV@L;L,@L)@L!@K$@K$@K/KKK\K\K\K@K0J@JlE@IW@I2I5#@I5#@IHO@HO@Hf@HH}@H@HuG@GGG@G߮G]@G.@G@GD@GR@F@Coty Sutherland 0:6.0.24-115Coty Sutherland 0:6.0.24-114Coty Sutherland 0:6.0.24-113Coty Sutherland 0:6.0.24-112Coty Sutherland 0:6.0.24-111Tomas Hoger 0:6.0.24-105Coty Sutherland 0:6.0.24-105Coty Sutherland 0:6.0.24-100Coty Sutherland 0:6.0.24-98Coty Sutherland 0:6.0.24-97Coty Sutherland 0:6.0.24-96Coty Sutherland 0:6.0.24-95Coty Sutherland 0:6.0.24-92Coty Sutherland 0:6.0.24-91Coty Sutherland 0:6.0.24-91Coty Sutherland 0:6.0.24-91Coty Sutherland 0:6.0.24-91Coty Sutherland 0:6.0.24-91Coty Sutherland 0:6.0.24-91Coty Sutherland 0:6.0.24-91David Knox 0:6.0.24-90David Knox 0:6.0.24-89David Knox 0:6.0.24-88David Knox 0:6.0.24-87David Knox 0:6.0.24-86David Knox 0:6.0.24-85David Knox 0:6.0.24-84David Knox 0:6.0.24-83David Knox 0:6.0.24-82David Knox 0:6.0.24-81David Knox 0:6.0.24-80David Knox 0:6.0.24-79David Knox 0:6.0.24-69David Knox 0:6.0.24-68David Knox 0:6.0.24-67David Knox 0:6.0.24-66David Knox 0:6,0.24-65David Knox 0:6.0.24-64David Knox 0:6.0.24-63David Knox 0:6.0.24-62David Knox 0:6.0.24-61David Knox 0:6.0.24-60David Knox 0:6.0.24-59David Knox 0:6.0.24-58David Knox 0:6.0.24-54David Knox 0:6.0.24-53David Knox 0:6.0.24-52David Knox 0:6.0.24-51David Knox 0:6.0.24-50David Knox 0:6.0.24-49David Knox 0:6.0.24-48David Knox 0:6.0.24-47David Knox 0:6.0.24-46David Knox 0:6.0.24-45David Knox 0:6.0.24-44David Knox 0:6.0.24-43David Knox 0:6.0.24-42David Knox 0:6.0.24-41David Knox 0:6.0.24-39David Knox 0:6.0.24-38David Knox 0:6.0.24-37David Knox 0:6.0.24-36David Knox 0:6.0.24-35David Knox 0:6.0.24-34David Knox 0:6.0.24-33David Knox 0:6.0.24-32David Knox 0:6.0.24-31David Knox 0:6.0.24-30David Knox 0:6.0.24-29David Knox 0:6.0.24-28David Knox 0:6.0.24-27David Knox 0:6.0.24-26David Knox 0:6.0.24-25David Knox 0:6.0.24-23David Knox 0:6.0.24-21David Knox 0:6.0.24-20David Knox 0:6.0.24-19David Knox 0:6.0.24-18David Knox 0:6.0.24-17David Knox 0:6.0.24-16David Knox 0:6.0.24-15David Knox 0:6.0.24-14David Knox 0:6.0.24-13David Knox 0:6.0.24-12David Knox 0:6.0.24-11David Knox 0:6.0.24-10David Knox 0:6.0.24-9David Knox 0:6.0.24-8David Knox 0:6.0.24-7David Knox 0:6.0.24-6David Knox 0:6.0.24-5david knox 0:6.0.24-4David Knox 0:6.0.24-3David Knox 0:6.0.24-2Alexander Kurtakov 0:6.0.24-1Alexander Kurtakov 0:6.0.20-2Alexander Kurtakov 0:6.0.20-1Fedora Release Engineering - 0:6.0.18-10.2Alexander Kurtakov 0:6.0.18-9.2Fedora Release Engineering - 0:6.0.18-9.1David Walluck 0:6.0.18-8.1David Walluck 0:6.0.18-8David Walluck 0:6.0.18-7David Walluck 0:6.0.18-6David Walluck 0:6.0.18-5David Walluck 0:6.0.18-4David Walluck 0:6.0.18-3David Walluck 0:6.0.18-2David Walluck 0:6.0.18-1Tom "spot" Callaway - 0:6.0.16-1.8David Walluck 0:6.0.16-1jpp.7.fc9David Walluck 0:6.0.16-1jpp.6.fc9David Walluck 0:6.0.16-1jpp.6.fc9David Walluck 0:6.0.16-1jpp.5.fc9David Walluck 0:6.0.16-1jpp.4.fc9David Walluck 0:6.0.16-1jpp.3.fc9David Walluck 0:6.0.16-1jpp.2.fc9David Walluck 0:6.0.16-1jpp.1.fc9Jason Corley - 0:6.0.16-1jppJason Corley - 0:6.0.14-2jppJason Corley 0:6.0.14-1jpp- Resolves: CVE-2020-9484 tomcat6: tomcat: Apache Tomcat Remote Code Execution via session persistence- Related: rhbz#1806803 Update patch to remove secret attribute renaming- Related: rhbz#1806803 Add IIS attributes to filter pattern and update secret logic- Resolves: rhbz#1806803 CVE-2020-1938 tomcat6: tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability* Sync with 6.9 - Resolves: rhbz#1498342 CVE-2017-12615 CVE-2017-12617 tomcat6: various flaws - Resolves: rhbz#1461291 CVE-2017-5664 tomcat6: tomcat: Security constrained bypass in error page mechanism - Resolves: rhbz#1441479 CVE-2017-5647 tomcat6: tomcat: Incorrect handling of pipelined requests when send file was used - Resolves: rhbz#1415824 The tomcat6 build is incompatible with the ECJ update- Sync with 6.8 - add CVE-2016-6816 follow-up patches and revert unreleased fixes. - Related: rhbz#1397484 CVE-2016-6816 Adding system property from asfbz-60594 to allow use of some un-encoded characters - Related: rhbz#1397484 CVE-2016-6816 Resolving a security regression (2017-6056) caused by CVE-2016-6816 - Reverts: rhbz#1415824 The tomcat6 build is incompatible with the ECJ update - Reverts: rhbz#1347778 The security manager doesn't work correctly- Related: rhbz#1415824 build. reverting ExcludeArch to fix composes- Resolves: rhbz#1413588 CVE-2016-8745 tomcat6: tomcat: information disclosure due to incorrect Processor sharing - Resolves: rhbz#1402665 CVE-2016-6816 tomcat6: tomcat: HTTP Request smuggling vulnerability due to permitting invalid character in HTTP requests - Resolves: rhbz#1415824 The tomcat6 build is incompatible with the ECJ update- Resolves: rhbz#1362211 CVE-2016-5388 Tomcat: CGI sets environmental variable based on user supplied Proxy request header - Resolves: rhbz#1368120 CVE-2016-6325 tomcat6: tomcat: tomcat writable config files allow privilege escalation- Resolves: rhbz#1367052 CVE-2015-5174 tomcat6: tomcat: URL Normalization issue - Resolves: rhbz#1367057 CVE-2016-0706 tomcat6: tomcat: directory disclosure - Resolves: rhbz#1367059 CVE-2016-0714 Security Manager bypass via persistence mechanisms - Resolves: rhbz#1367055 CVE-2015-5345 Directory disclosure- Resolves: rhbz#1327238 rpm -V tomcat6 fails due on /var/log/tomcat6/catalina.out - Resolves: rhbz#1347778 The security manager doesn't work correctly- Related: rhbz#1084426 Reverting to prevent Satellite installation issues mentioned in rhbz-1302761- Resolves: rhbz#1293290 CVE-2014-7810 tomcat6 security manager bypass via EL expressions- Resolves: rhbz#886653 Tomcat6 files should be owned by user / group tomcat- Resolves: rhbz#1155509 tomcat6 packages are arch dependent- Resolves: rhbz#1264559 Correct behaviour of ResourceBundleELResolver.- Resolves: rhbz#1268352 Resolving NIO connector memory leak.- Resolves: rhbz#1134600 Resolve STRICT_SERVLET_COMPLIANCE issues.- Resolves: rhbz#1072484 Resolve fix translation problem affecting IBM JDK.- Resolves: rhbz#1221877 Add support for disableURLRewriting.- Related: rhbz#1042811 left over test value in the conf- Resolves: rhbz#1042811 tomcat6 service restarts will cause a - duplicated command-line arguments- Related: rhbz#1022061 changed in init file. Remove test - in function stop for result after initial command to - stop.- Resolves: rhbz#1128396 NPE in chunked encoding. - Regenerated patches for 4322 and 0227- Resolves: rhbz#1068689 Add option to disable log rotation - in FileHandler- Resolves: CVE-2014-0227 Limited DoS in chunked transfer- Resolves: rhbz#1022061 Tomcat init script needs to be adjusted to kill tomcat - if stop is unsuccessful- Resolves: rhbz#1054817 Mark Tomcat Manager web.xml as - config in spec- Resolves: rhbz#1031327 Backport apache 50072 blank responses- Resolves: rhbz#1183252 Tomcat breaks in serving large files - greater than 1.7 mb and under high load and high threading- Related: CVE-2013-4590 - remove xml schema names javaee_5, - javaee_web_services_1_2, and javaee_web_services_1_2_client - from descriptor.DigesterFactory initialization. These - schema definitions are not relevant to 6.0.24 as the version - of their spec did not exist at the time. - Resolves: rhbz#1140855 - request parameter truncated- Related: rhbz#1140301 - have to bump the nvr to be greater - than 6.5.z- Resolves: rhbz#1140301 - reverse changes of 845786. - Rebuilding for compose.- Resolves: CVE-2013-4590 - Resolves: CVE-2014-0119- Related: CVE-2014-0075 incomplete- Related: CVE-2014-0050 - Related: CVE-2013-4322- Resolves: CVE-2014-0099 - Resolves: CVE-2014-0096 - Resolves: CVE-2014-0075- Resolves: CVE-2014-0050- Resolves: CVE-2013-4322 CVE-2013-4286. Branched from - rhel-6.5- Related: rhbz 915447 Introduced a space char in TOMCAT_GROUP- Related: rhbz 915447 Typo in conf and sysconf- Related: rhbz 915447 can't start with group other than tomcat - changes in init script. Added TOMCAT_GROUP to sysconfig and - tomcat6.conf. Also changed default to the group that user - tomcat belongs.- Related: CVE-2012-3439 Digest Authentication. Fixed typo - in the patch file.- Resolves: CVE-2012-3439 - Resolves: CVE-2012-4534 - Resolves: CVE-2012-3546 - Increment build number to exceed 6_4 build number. Demanded - by rpmdiff- Resolves: rhbz 845786 webapps-docs contained empty files. - Build will fail of architectures ppc s390x ppc64. Use - target rhel-6.5-noarch-candidate - Resolves: rhbz 915447 can't start with group other than tomcat - changes in init script - Resolves: rhbz 950647 Error in checkpidfile of init script - Resolves: rhbz 977685 Full implementation of juli and juli - adapters. Jars placed in new extras directory - Resolves: 960225 Status script does not return proper PID- Resolves: CVE-2013-2067 session fixation- Related: rhbz#955977 CVE-2013-1976- Related: rhbz#955977 CVE-2013-1976 Changed location of - TOMCAT_LOG to /var/log where only root can write to it. Touching - TOMCAT_LOG is no longer necessary- Resolves: rhbz#955977 CVE-2013-1976 Improper TOMCAT_LOG management in - init script- Related: rhbz 576540 - Javadoc is not being generated correctly by the build- Resolves: rhbz 576540 - regression init script in the - wrong place. Changed _initrddir definition herein to point to the - right place.- Resolves: rhbz 857066 apache bz 48843 ArrayIndexOutofBounds- Resolves: rhbz 847288 classloader deadlock compiler JSPs - Resolves: rhbz 785954 HTML filtering needed - Resolves: rhbz 798617 init gives incorrect status- Resolves: rhbz 757632 regression- Resolves: CVE-2012-0022 regression. Change made to patch.- Resolves: rhbz# 802396. Changes made to init script.- Resolves cve-2012-0022 (2011-4858) rhbz 783728- Resolves: rhbz 782400 - remove redhat-lsb dependency - Resolves: rhbz 726169 (783407) - Unable to compile class for JSP - Resolves: rhbz 783567 - tag attributes parsing throws exception- Resolves: rhbz 757632 - version arg results in CNFException - changes made to initscript.- resolves: rhbz 748813 NPE w/no data in chunked POST request - Not included in 6.2. Slated for 6.3- resolves: cve-2011-3190 rhbz 738504 - resolves: cve-2011-2204 rhbz 738504 - resolves: cve-2011-2526 rhbz 738504 - resolves: cve-2011-1184 rhbz 738504 - resolves: rhbz 698624 - revisited- resolves: rhbz 726169 - jsp1.1 regression exception - Not included in 6.2 slated for 6.3- resolves: rhbz 687968 - tomcat6 broken when LANG="fr_FR"- resolves: rhbz 701759 - hardcoded catalina.out - Not included in 6.2 slated for 6.3- resolves: rhbz 695284 - multiple instances logging fiasco- Resolves: rhbz 698624 - inet4address can't be cast to String- Resolves: rhbz 656403 - cve-2010-4172 jsp syntax error- Resolves: rhbz#697504 initscript logging location- Resolves: rhbz#656403, rhbz#675926, rhbz#676011 - CVE-2010-4172, CVE-2010-3718, CVE-2011-0013, CVE-2010-4476, - CVE-2011-0534- Resovles rhbz#695284 - wrapper logs to different locations - CVE-2010-4172, CVE-2011-0013, CVE-2010-3718 commented out - until needed.- naming-factory-dbcp missing fix in tomcat6.conf - Add Obsoletes for log4j- Add log4j to package lib. Corrected typo in log4 Provides - epock versus epoch- Installed permissions do not allow tomcat to start - incrementing NVR so yum won't get confused with the zstream- Resolves: rhbz 678671 - useradd sets shell to nologin - dangling symlink for log4j. Added it as R: and R(post)- Resolves: 678671 - tomcat user requires login shell- Resolves: rhbz#636997 Additionally created instances of tomcat - are broken- Resolves: CVE-2011-0534 rhbz# 675926- Resolves: rhbz# 661244 missing tomcat6-juli link - Fixed symlinks to commons-collections and log4j in libdir - Removed log4j package- Replacing commons-xxxx-tomcat5 with jakarta-commons-xxxx- Resolves: rhbz#636997 - Additionally created instances of tomcat are - broken- Resolves: rhbz#617501 CVE-2010-2227- Added 2227 patch- fixed servlet-api typo- Resolves: rhbz#584699. A respin was required to fix post and - postun for el. Updated EL-spec to 2.1 from 1.0. Tomcat6 uses - elspec 2.1- Resolves: rhbz#584699 initscript collected problems LSB - compliant. Not complete yet. Return values are correct and - usage function has been implemented.- Resolves: rhbz#606822 CVE-2010-1157- Resolves: rhbz#582037 Revert to Java 1.5. Also fixed Error - deploying web application.- Resolves: rhbz#584699 - and two other bugs along with - various spec flaws fixed.- Build and run using gcj 1.5. Spec refactored. JSP examples - are working.- Patched spec file to avoid sinjdoc issue- Adding patch for setPerformancePrefernces- increment build number- Removed prerun lib and post WEB-INF/lib. Moved build-jar-repos to - after the installs. Added Requires and BuildRequires for jakarta- - commons-{dbcp,pool,collections}-tomcat5 and ecj. Changed define macro to - global.- Revert: Revert JDK/Java Requires and BuildRequires to version 1.5 versus 1.6- Update to 6.0.24.- Drop file requires on /usr/share/java/ecj.jar.- Update to 6.0.20. Fixes CVE-2009-0033,CVE-2009-0580.- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Add OSGi manifest for servlet-api.- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- build for Fedora- fix directory ownership- add Requires for update-alternatives- use lsb_release instead of lsb-release to get the distributor- fix initscript messages on Mandriva Linux - fix help message in initscript- redefine %_initrddir for FHS-compliance - make initscript LSB-complaint- fix status in initscript- remove initscripts and /sbin/service requirement - call initscript directly without using /sbin/service - require /sbin/chkconfig instead of chkconfig - remove chkconfig requirement from packages that don't require it- 6.0.18 - Resolves: CVE-2008-1232, CVE-2008-1947, CVE-2008-2370, CVE-2008-2938 - fix definition of java.security.policy with d%{name} start-security - don't pass $CATALINA_OPTS with d%{name} stop - redefine tempdir and workdir for tmpwatch workaround - change eclipse-ecj references to ecj- drop repotag- version jsp and servlet Provides with their spec versions - remove Obsoletes/Provides for servletapi6 package as it can co-exist - check for java-functions existence in wrapper script - move d%{name} to %{name} and create symlink for d%{name} - improve status function in initscript - change license to ASL 2.0 again as per Fedora guidelines- remove Requires: tomcat-native - put back original JPackage Group (except javadoc) and License tags - add Provides for jsp and servlet - use ant macro - build and install sample webapp - call /sbin/service to stop service on uninstall - remove references to $RPM_BUILD_DIR - use copy instead of move to fix short-circuit install build - remove prebuilt sample.war - remove Thumbs.db files - add Requires: java >= 0:1.6.0- remove Requires: tomcat-native - put back original JPackage Group (except javadoc) and License tags - add Provides for jsp and servlet - use ant macro - build and install sample webapp - call /sbin/service to stop service on uninstall - remove references to $RPM_BUILD_DIR - use copy instead of move to fix short-circuit install build - remove prebuilt sample.war - remove Thumbs.db files - add Requires: java >= 0:1.6.0- explicitly unset CLASSPATH - explicitly set OPT_JAR_LIST to include ant/ant-trax- remove BuildRequires: sed - remove specific references to icedtea- add digest and tool-wrapper scripts - Requires: tomcat-native- use %{_var} for appdir instead of /srv - use ${JAVACMD} for java executable in wrapper script - use built-in status function in initscript where possible - add missing require on procps for status function - fix java.library.path setting in %{_sysconfdir}/sysconfig/%{name} - add patch to document webapps in %{_sysconfdir}/%{name}/tomcat-users.xml - remove %{appdir}/ROOT/admin - move %{_bindir}/d%{name} to %{_sbindir}/d%{name}- use %{_initrddir} macro instead of %{_sysconfdir}/init.d (rhbz #153187) - fix java.library.path setting in %{name}.conf (rhbz #253605) - fix incorrect initscript output (rhbz #380921) - update initscript (rhbz #247077) - add logrotate support - fix strange-permission - fix %prep - replace /var with %{_var} - replace %{_localstatedir} with %{_var} - use %{logdir} where possible - call build-jar-repository with full path in scriptlets - remove file-based requires - build with icedtea and set as the default JAVA_HOME in %{name}.conf - fix non-standard-group - change ecj references to eclipse-ecj - change Apache Software License 2.0 to ASL 2.0 for rpmlint- update to 6.0.16- add /etc/tomcat6/Catalina/localhost (Alexander Kurtakov)- first JPackage release  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~0:6.0.24-115.el6_10  docsBUILDING.txtRELEASE-NOTES.txtRUNNING.txtWEB-INFweb.xmlaio.htmlapiindex.htmlappdevbuild.xml.txtdeployment.htmlindex.htmlinstallation.htmlintroduction.htmlprocesses.htmlsamplebuild.xmldocsREADME.txtindex.htmlsrcmypackageHello.javawebWEB-INFweb.xmlhello.jspimagestomcat.gifindex.htmlsource.htmlweb.xml.txtapr.htmlarchitectureindex.htmloverview.htmlrequestProcessrequestProcess.htmlrequestProcess.pdfroseModel.mdlstartupstartup.htmlserverStartup.pdfserverStartup.txtbalancer-howto.htmlbuilding.htmlcgi-howto.htmlchangelog.htmlclass-loader-howto.htmlcluster-howto.htmlconfigajp.htmlcluster-channel.htmlcluster-deployer.htmlcluster-interceptor.htmlcluster-listener.htmlcluster-manager.htmlcluster-membership.htmlcluster-receiver.htmlcluster-sender.htmlcluster-valve.htmlcluster.htmlcontext.htmlengine.htmlexecutor.htmlglobalresources.htmlhost.htmlhttp.htmlindex.htmllisteners.htmlloader.htmlmanager.htmlrealm.htmlresources.htmlserver.htmlservice.htmlsystemprops.htmlvalve.htmlconnectors.htmldefault-servlet.htmldeployer-howto.htmldevelopers.htmlextras.htmlfuncspecsfs-admin-apps.htmlfs-admin-objects.htmlfs-admin-opers.htmlfs-default.htmlfs-invoker.htmlfs-jdbc-realm.htmlfs-jndi-realm.htmlfs-memory-realm.htmlindex.htmlmbean-names.htmlhtml-manager-howto.htmlimagesadd.gifasf-logo.gifcode.gifdesign.gifdocs.giffix.gifprinter.giftomcat.giftomcat.svgupdate.gifvoid.gifindex.htmlintroduction.htmljasper-howto.htmljndi-datasource-examples-howto.htmljndi-resources-howto.htmllogging.htmlmanager-howto.htmlmaven-jars.htmlmbeans-descriptor-howto.htmlmonitoring.htmlproxy-howto.htmlrealm-howto.htmlsecurity-manager-howto.htmlsetup.htmlssi-howto.htmlssl-howto.htmltribesfaq.htmlintroduction.htmlsetup.htmlvirtual-hosting-howto.htmlwindows-service-howto.html/var/lib/tomcat6/webapps//var/lib/tomcat6/webapps/docs//var/lib/tomcat6/webapps/docs/WEB-INF//var/lib/tomcat6/webapps/docs/api//var/lib/tomcat6/webapps/docs/appdev//var/lib/tomcat6/webapps/docs/appdev/sample//var/lib/tomcat6/webapps/docs/appdev/sample/docs//var/lib/tomcat6/webapps/docs/appdev/sample/src//var/lib/tomcat6/webapps/docs/appdev/sample/src/mypackage//var/lib/tomcat6/webapps/docs/appdev/sample/web//var/lib/tomcat6/webapps/docs/appdev/sample/web/WEB-INF//var/lib/tomcat6/webapps/docs/appdev/sample/web/images//var/lib/tomcat6/webapps/docs/architecture//var/lib/tomcat6/webapps/docs/architecture/requestProcess//var/lib/tomcat6/webapps/docs/architecture/startup//var/lib/tomcat6/webapps/docs/config//var/lib/tomcat6/webapps/docs/funcspecs//var/lib/tomcat6/webapps/docs/images//var/lib/tomcat6/webapps/docs/tribes/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnu                ASCII textGIF image data, version 89a, 1 x 1GIF image data, version 89a, 100 x 71GIF image data, version 89a, 130 x 92GIF image data, version 89a, 20 x 20GIF image data, version 89a, 32 x 29GIF image data, version 89a, 387 x 100HTML document textSVG Scalable Vector Graphics imageXML 1.0 document textdirectoryexported SGML document text?7zXZ !#,u]"k%3z;:C$ݚ8u  9^lLZVl|@E;i/ɑ@6yk/ MХ%.7(/y D$˪>5Ќ7l8gll#&-1e ,Ť#3䴀⨒F;dYS,zPgilհƹ;Z[M8Y.)卼.hn^Ͳj5uԾd=vO5K[G7ߴy2*|u+dX%WAsY3Jg] Q#MV~n#=Z< NNj(\LpEv|+ĺ5!;Phbe;N|Z6`€쟢*z8 9xBUqO4)>ҚgD]&mXFb=TTAN+;⍦0Ay(ƵV[lji}n-(wӔ|w%w 3/T(N u#`5c5jG 60ͳcUp&?׻Cb\1%0X5;A 4'fNBR`=x|/Nx/ T8fIagm饆tk'ˀ,ƪ daviB'#|~zN$!zMQ^T-WыǘW`Ü<\)Qnۡyob՞;ĶX@FbcRw$-ڤ~b([نזJ2y@abqTh`6Rqho7҅9fV䫇Lr@.vr(bÓ+J¨DQh7?+e* ;T@*WS|=ޗE uz?_+!ӡL 3x-Lj)@>x-Z}DB(~n,s I8{Z+*/=KPjʝ՚OxAJL>8m2+: _,~8f^ uFka62^JMп0}k[1A/Pa\p8f۵u]^*%|C$ɨb;);Ķa!*z ܏d`E~"e SWxm"[?5GYt<|~F |nV"mWBΔH֣,SÔAǴ߭ ҽ00'MBT@bG߶M7B'Հ7ĄCwma.텗Fն3MrZ6MZ!GFmocf>j'ƥ]b~eZ;p#Ie=$gaR3efcRK]LN7l ##* L"/xV 5J2؊BJ|d{$b %?z= LZ {0`\`߄ ؇yOa[Bӛ]ֶJfTejOIDkۢ8|;~sGwuROty\$)l >];tsv+"ʵ.}};(~?Y<m&J{|tugyUU%C#)|{C { 2BHg{x;i@sƺ7w 6~؋ M"m ?uim=GVT7g4`LZ'3l4+?3i#-xH,}Zv&VʖP(rV3~ 8npUhXr}E Ywcqq˿ib".\OԻ -~p|b_<$97/WU-HQdweܣk^P>4?iSO hdeǹ.T`#5BE?"_+B\h7_k8䣅̽n^"_4&ɆOf(Aߝ Z3ȑ"d.kӭXoF)C2}",yb4dՙyqO-Au:i-+WuB,9p@5%}q'xw @%m|-;uNS *W[]“iy`a"WKrcGC(B%A'ۚTϹ#?? D/8s=Lu}Bk>)+F jTd-H)~ V (B /iim-_AZr$Nnil6ղjN9;M^t (y^#p>ƛ~:火gQ0zt>B4.@- Aᱣ#捤|E[HLiBȄVIp&O,6a&ʹloՕLT׫6?;0nL΅¯/M{.17qÕHmefb}QuquN:@=DvhQ/oz꛲U^:#E9,ʱUH,;&'?Z[2[.̊>(Ks*P(-i? }jx2"*t#6e Rq* DVڛCZƱ4IVQـFP>>R d9L>,ۡ$bime{Lm t{aw7bD:iNߘ;P׶r#=J/2>Rܦd`!n~$̧bu}E˜9 G=\ *9I&Dh E U4}NOXn.i<]obR$IdV5>W,mB>R4N4^*yiEp@jj^L}HY%6I'"a#X2$9 YZ