lucene-solr (3.6.2+dfsg-11) unstable; urgency=medium * Team upload. * Switch to compat level 11. * Declare compliance with Debian Policy 4.1.3. * Fix CVE-2017-12629: possible remote code execution by exploiting XXE. For security reasons the RunExecutableListener class was permanently removed. * Fix CVE-2017-3163: path traversal vulnerability. (Closes: #867712) -- Markus Koschany Sun, 14 Jan 2018 14:32:32 +0100 lucene-solr (3.6.2+dfsg-10) unstable; urgency=medium * Team upload. * Remove obsolete Resources className directive as it does not work with Tomcat8. Thanks to Matthias Liertzer for the report. (Closes: #856626) -- Markus Koschany Thu, 30 Mar 2017 20:24:00 +0200 lucene-solr (3.6.2+dfsg-9) unstable; urgency=medium * Team upload. [ Emmanuel Bourg ] * Switched the dependencies to tomcat8, libservlet3.1-java and jetty9 * Standards-Version updated to 3.9.8 * Use a secure Vcs-* URL * Fixed the watch file [ tony mancill ] * Add Dutch translation of debconf messages. (Closes: #835136) Thank you to Frans Spiesschaert for the translation. -- Emmanuel Bourg Mon, 24 Oct 2016 17:10:19 +0200 lucene-solr (3.6.2+dfsg-8) unstable; urgency=medium * Team upload. * Transition to bnd 2.1.0. * Fix Lintian warning empty-short-license-in-dep5-copyright. * Fix Lintian warnings command-with-path-in-maintainer-script. * Vcs-Browser: Use https. -- Markus Koschany Thu, 19 Nov 2015 22:13:50 +0100 lucene-solr (3.6.2+dfsg-7) unstable; urgency=medium * Add OSGi metadata to JAR manifests * Add Jakub Adam to Uploaders * Update file paths in d/copyright -- Jakub Adam Mon, 03 Aug 2015 15:49:56 +0200 lucene-solr (3.6.2+dfsg-6) unstable; urgency=medium * Team upload. [ Emmanuel Bourg ] * Removed the dependency on libgeronimo-stax-1.2-spec-java * Fixed a test failure with commons-codec 1.10 * Fixed a test failure with Java 8 (Closes: #760927) * Use XZ compression for the upstream tarball * debian/watch: No longer use the defunct githubredir.debian.net redirector [ Victor Seva ] * solr-tomcat: allow tomcat7-user as depends (Closes: #606138) -- Emmanuel Bourg Mon, 13 Jul 2015 14:45:06 +0200 lucene-solr (3.6.2+dfsg-5) unstable; urgency=medium * Team upload. * Fixed the deployment with Jetty 8 (Closes: #752547, #767525) * Enable the symbolic links with Jetty (Closes: #701876) * Fixed the path to dpkg-statoverride in solr-jetty.postrm (Closes: #767519) -- Emmanuel Bourg Fri, 31 Oct 2014 19:28:25 +0100 lucene-solr (3.6.2+dfsg-4) unstable; urgency=medium * Team upload. * Switched the dependencies to tomcat7, libservlet3.0-java and jetty8 * Fixed a format issue with CVE-2013-6397.patch * Standards-Version updated to 3.9.6 (no changes) -- Emmanuel Bourg Mon, 06 Oct 2014 15:47:56 +0200 lucene-solr (3.6.2+dfsg-3) unstable; urgency=medium * Team upload. * Add tomcat-coyote to debian/build-jars to address FTBFS. (Closes: #749364) * Update Vcs- URLs in debian/control. * Use debhelper 9. * Bump Standards-Version to 3.9.5. -- tony mancill Tue, 10 Jun 2014 22:29:19 -0700 lucene-solr (3.6.2+dfsg-2) unstable; urgency=low * Fixes for new security vulnerabilities (Closes: #731113): - debian/patches/CVE-2013-6397.patch: Fix DocumentAnalysisRequestHandler to correctly use EmptyEntityResolver to prevent loading of external entities like UpdateRequestHandler does. CVE-2013-6397 - debian/patches/CVE-2013-6407_CVE-2013-6408.patch: XML and XSLT UpdateRequestHandler should not try to resolve external entities. This improves speed of loading e.g. XSL-transformed XHTML documents. CVE-2013-6407 Fix XML parsing in XPathEntityProcessor to correctly expand named entities, but ignore external entities. CVE-2013-6408 -- James Page Sat, 14 Dec 2013 22:07:54 +0000 lucene-solr (3.6.2+dfsg-1) unstable; urgency=low * Upload to unstable. -- James Page Thu, 16 May 2013 10:45:27 +0100 lucene-solr (3.6.2+dfsg-1~exp1) experimental; urgency=low [ tony mancill ] * solr-jetty: correct symlink to solr in /var/lib/jetty/webapps/ (Closes: #696347) [ James Page ] * New upstream release. * d/copyright: Removed surplus GPL-2 paragraph. * d/control: Tidied short descriptions. -- James Page Mon, 07 Jan 2013 14:23:47 +0000 lucene-solr (3.6.1+dfsg-1) experimental; urgency=low * New upstream release. * Add dependency on JDK for solr-jetty (LP: #1046732): - d/control: Add extra Depends on default-jdk | java5-jdk as jetty requires a full JDK to support use of JSP's which solr uses. -- James Page Wed, 21 Nov 2012 09:31:05 +0000 lucene-solr (3.6.0+dfsg-1) unstable; urgency=low * Initial release. (Closes: #594027) -- James Page Tue, 29 May 2012 17:32:24 +0100