--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-11356
2009-11-11 14:15:57
--------------------------------------------------------------------------------

Name        : tomcat6
Product     : Fedora 10
Version     : 6.0.20
Release     : 1.fc10
URL         : https://tomcat.apache.org/
Summary     : Apache Servlet/JSP Engine, RI for Servlet 2.5/JSP 2.1 API
Description :
Tomcat is the servlet container that is used in the official Reference
Implementation for the Java Servlet and JavaServer Pages technologies.
The Java Servlet and JavaServer Pages specifications are developed by
Sun under the Java Community Process.

Tomcat is developed in an open and participatory environment and
released under the Apache Software License version 2.0. Tomcat is intended
to be a collaboration of the best-of-breed developers from around the world.

--------------------------------------------------------------------------------
Update Information:

Fix for CVE-2008-5515, CVE-2009-0033, CVE-2009-0580, CVE-2009-0781, and
CVE-2009-0783.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Nov  9 2009 Alexander Kurtakov  0:6.0.20-1
- Update to 6.0.20. Fixes CVE-2009-0033,CVE-2009-0580.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #533903 - CVE-2009-0033 CVE-2009-0580 CVE-2009-0783 CVE-2008-5515 CVE-2009-0781 Multiple tomcat6 vulnerabilities [Fedora all]
        https://bugzilla.redhat.com/show_bug.cgi?id=533903
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update tomcat6' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
https://www.redhat.com/mailman/listinfo/fedora-package-announce

Fedora 10: tomcat6 Security Update

November 27, 2009
Fix for CVE-2008-5515, CVE-2009-0033, CVE-2009-0580, CVE-2009-0781, and CVE-2009-0783.

Summary

Tomcat is the servlet container that is used in the official Reference

Implementation for the Java Servlet and JavaServer Pages technologies.

The Java Servlet and JavaServer Pages specifications are developed by

Sun under the Java Community Process.

Tomcat is developed in an open and participatory environment and

released under the Apache Software License version 2.0. Tomcat is intended

to be a collaboration of the best-of-breed developers from around the world.

Update Information:

Fix for CVE-2008-5515, CVE-2009-0033, CVE-2009-0580, CVE-2009-0781, and CVE-2009-0783.

Change Log

* Mon Nov 9 2009 Alexander Kurtakov 0:6.0.20-1 - Update to 6.0.20. Fixes CVE-2009-0033,CVE-2009-0580.

References

[ 1 ] Bug #533903 - CVE-2009-0033 CVE-2009-0580 CVE-2009-0783 CVE-2008-5515 CVE-2009-0781 Multiple tomcat6 vulnerabilities [Fedora all] https://bugzilla.redhat.com/show_bug.cgi?id=533903

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update tomcat6' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : tomcat6
Product : Fedora 10
Version : 6.0.20
Release : 1.fc10
URL : https://tomcat.apache.org/
Summary : Apache Servlet/JSP Engine, RI for Servlet 2.5/JSP 2.1 API