Bug 96468 - www/jakarta-tomcat5: Jakarta Tomcat 5 is not up to date (security-related)
Summary: www/jakarta-tomcat5: Jakarta Tomcat 5 is not up to date (security-related)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Sam Lawrance
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-04-28 16:30 UTC by Yann Golanski
Modified: 2006-09-11 14:01 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Yann Golanski 2006-04-28 16:30:18 UTC
Jakarta Tomcat version 5 has a security issue that is fixed in newer version.  Updating the version of the port should fix it.

Fix: 

Update Jakarta to latest release version.
How-To-Repeat: # cd www/jakarta-tomcat5/
# make
===>  jakarta-tomcat-5.0.30_3 has known vulnerabilities:
=> tomcat -- Tomcat Manager cross-site scripting.
   Reference: <http://www.FreeBSD.org/ports/portaudit/26a08c77-32da-4dd7-a884-a76fc49aa824.html>
=> Please update your ports tree and try again.
*** Error code 1

Stop in /usr/ports/www/jakarta-tomcat5.
Comment 1 Vasil Dimov freebsd_committer freebsd_triage 2006-04-28 16:41:49 UTC
On Fri, Apr 28, 2006 at 03:29:03PM +0000, Yann Golanski wrote:
> 
> >Synopsis:       Jakarta Tomcat 5 is not up to date.
[...]
> Jakarta Tomcat version 5 has a security issue that is fixed in newer version.  Updating the version of the port should fix it. 

Did you tried that? If it works for you, can you please send a patch?

Btw it's always a good idea to CC: the maintainer and include
category/port in the synopsis.

-- 
Vasil Dimov
gro.DSBeerF@dv

Testing can show the presence of bugs, but not their absence.
                -- Edsger W. Dijkstra
Comment 2 Edwin Groothuis freebsd_committer freebsd_triage 2006-04-28 22:53:28 UTC
State Changed
From-To: open->feedback

Awaiting maintainers feedback
Comment 3 Sam Lawrance freebsd_committer freebsd_triage 2006-05-15 09:11:07 UTC
State Changed
From-To: feedback->open

Maintainer timeout. 


Comment 4 Sam Lawrance freebsd_committer freebsd_triage 2006-05-15 09:11:07 UTC
Responsible Changed
From-To: freebsd-ports-bugs->lawrance

I need to fix some other problems with tomcat, might as well 
grab this one too.
Comment 5 Mark Linimon freebsd_committer freebsd_triage 2006-09-11 10:17:44 UTC
State Changed
From-To: open->feedback

lawrence, what's the state of this?  The port itself is still at the 
vulnerable version, but it is not so marked.
Comment 6 Sam Lawrance freebsd_committer freebsd_triage 2006-09-11 14:00:13 UTC
State Changed
From-To: feedback->closed

Fixed, thanks.