Re: Tomcat 8 security update

2016-05-29 Thread Moritz Muehlenhoff
On Mon, May 30, 2016 at 08:42:52AM +0200, Emmanuel Bourg wrote: > Le 30/05/2016 à 01:24, Markus Koschany a écrit : > > > OK, then let's update the third line to > > > > chown -Rh $TOMCAT8_USER:$TOMCAT8_GROUP /etc/tomcat8/Catalina > > /var/lib/tomcat8/webapps /var/lib/tomcat8/lib > > I don't feel

Re: Tomcat 8 security update

2016-05-29 Thread Emmanuel Bourg
Le 30/05/2016 à 01:24, Markus Koschany a écrit : > OK, then let's update the third line to > > chown -Rh $TOMCAT8_USER:$TOMCAT8_GROUP /etc/tomcat8/Catalina > /var/lib/tomcat8/webapps /var/lib/tomcat8/lib I don't feel comfortable fixing #825786 directly in a stable security update. It would be sa

Re: Tomcat 8 security update

2016-05-29 Thread Markus Koschany
On 30.05.2016 01:00, Emmanuel Bourg wrote: > Le 30/05/2016 à 00:12, Markus Koschany a écrit : > >> I have prepared a security update for Tomcat 8 fixing 7 CVEs. In >> addition I would like to fix #825786. We currently overwrite file >> permissions in /etc/tomcat8/ unconditionally which could break

Re: Tomcat 8 security update

2016-05-29 Thread Emmanuel Bourg
Le 30/05/2016 à 00:12, Markus Koschany a écrit : > I have prepared a security update for Tomcat 8 fixing 7 CVEs. In > addition I would like to fix #825786. We currently overwrite file > permissions in /etc/tomcat8/ unconditionally which could break user > specific changes on upgrade. The fix is to

Tomcat 8 security update

2016-05-29 Thread Markus Koschany
Hi, I have prepared a security update for Tomcat 8 fixing 7 CVEs. In addition I would like to fix #825786. We currently overwrite file permissions in /etc/tomcat8/ unconditionally which could break user specific changes on upgrade. The fix is to revert to default file permissions root:root (rw-r-r