update tomcat55 to 5.5.33 built clean in tinderbox http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32 low: Cross-site scripting CVE-2011-0013 The HTML Manager interface displayed web applciation provided data, such as display names, without filtering. A malicious web application could trigger script execution by an administartive user when viewing the manager pages. This was fixed in revision 1057518. This was identified by the Tomcat security team on 12 Nov 2010 and made public on 5 Feb 2011. Affects: 5.5.0-5.5.31
Class Changed From-To: maintainer-update->change-request Fix category (submitter is not maintainer) (via the GNATS Auto Assign Tool)
Responsible Changed From-To: freebsd-ports-bugs->jhelfman Submitter has GNATS access (via the GNATS Auto Assign Tool)
Maintainer of www/tomcat55, Please note that PR ports/154787 has just been submitted. If it contains a patch for an upgrade, an enhancement or a bug fix you agree on, reply to this email stating that you approve the patch and a committer will take care of it. The full text of the PR can be found at: http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/154787 -- Edwin Groothuis via the GNATS Auto Assign Tool edwin@FreeBSD.org
State Changed From-To: open->feedback Awaiting maintainers feedback (via the GNATS Auto Assign Tool)
I am uncertain how this happened, as I updated all applicable fields for email to be jhelfman@experts-exchange.com, however it indicates jhelfman@freebsd.org. Can you please update all email addresses to reflect this address? I am maintainer, and do approve of this. Thanks! -- Jason Helfman System Administrator experts-exchange.com http://www.experts-exchange.com/M_4830110.html E4AD 7CF1 1396 27F6 79DD 4342 5E92 AD66 8C8C FBA5
wen 2011-02-15 07:22:27 UTC FreeBSD ports repository Modified files: www/tomcat55 Makefile distinfo Log: - Update to 5.5.33 PR: ports/154787 Submitted by: Jason Helfman <jhelfman@experts-exchange.com> (maintainer) Revision Changes Path 1.58 +3 -4 ports/www/tomcat55/Makefile 1.27 +2 -2 ports/www/tomcat55/distinfo _______________________________________________ cvs-all@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/cvs-all To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
State Changed From-To: feedback->closed Committed. Thanks!
Responsible Changed From-To: jhelfman->wen Fix up bogus email address which led to bogus assignment.