Bug#263201: tomcat4 should be upgraded to 4.1.x in sarge

Jerome Lacoste Jerome Lacoste <jerome@coffeebreaks.org>, 263201@bugs.debian.org
Tue Aug 3 04:24:09 2004


Package: tomcat4
Version: 4.0.4-4
Severity: important

tomcat 4.0.4 is more than 2 years old. We cannot ship sarge with such an old and important application.
The release problem may be related to log4j release critical issue. See issue #221236
But both issues should be worked out at the same time if we want to manage to get a recent tomcat in sarge.
There may also be security issues with old tomcat.
E.g. thhp://www.securityfocus.com/archive/1/292936/



-- System Information:
Debian Release: testing/unstable
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)
Kernel: Linux 2.4.24-1-686
Locale: LANG=C, LC_CTYPE=C

Versions of packages tomcat4 depends on:
ii  adduser                       3.51       Add and remove users and groups
ii  java-virtual-machine-dummy    1.0        Dummy package providing java-virtu
ii  java2-runtime-dummy [java2-ru 1.0        Dummy package providing java2-runt
ii  libtomcat4-java               4.0.4-4    Java Servlet engine -- core librar
ii  logrotate                     3.6.5-2    Log rotation utility
ii  sysvinit                      2.85-9     System-V like init.

-- no debconf information