https://bz.apache.org/bugzilla/show_bug.cgi?id=59604
Mark Thomas changed:
What|Removed |Added
Status|NEW |NEEDINFO
--- Comment #12 from Mark Thoma
https://bz.apache.org/bugzilla/show_bug.cgi?id=58626
--- Comment #18 from Mark Thomas ---
(In reply to Michael Osipov from comment #17)
> Quite a nice solution. Line 274 has too many spaces in it.
Ack. If this works, I'll fix that before committing it.
> I will test that next week in a HP-UX 1
https://bz.apache.org/bugzilla/show_bug.cgi?id=59604
Dave changed:
What|Removed |Added
Status|NEEDINFO|NEW
--- Comment #11 from Dave ---
... continue
https://bz.apache.org/bugzilla/show_bug.cgi?id=59604
--- Comment #10 from Dave ---
Created attachment 33885
--> https://bz.apache.org/bugzilla/attachment.cgi?id=33885&action=edit
log file with only ROOT app
--
You are receiving this mail because:
You are the assignee for the bug.
---
https://bz.apache.org/bugzilla/show_bug.cgi?id=59604
--- Comment #9 from Dave ---
Created attachment 33884
--> https://bz.apache.org/bugzilla/attachment.cgi?id=33884&action=edit
modified web.xml for ROOT
I stripped out the comments and the following:
--
You are receiving this mail because:
Y
https://bz.apache.org/bugzilla/show_bug.cgi?id=58626
--- Comment #17 from Michael Osipov <1983-01...@gmx.net> ---
(In reply to Mark Thomas from comment #16)
> Created attachment 33883 [details]
> Proposed patch for Tomcat 9.0.x, version 1
>
> I don't have an HP-UX box to test with but the describ
https://bz.apache.org/bugzilla/show_bug.cgi?id=59604
--- Comment #8 from Christopher Schultz ---
(In reply to Dave from comment #6)
> We might be able to provide access to z/OS shell. Meanwhile, what kind of
> diagnostic data I can collect for debugging purpose?
Can you perform an MD5 signature
https://bz.apache.org/bugzilla/show_bug.cgi?id=59604
Mark Thomas changed:
What|Removed |Added
Status|NEW |NEEDINFO
--- Comment #7 from Mark Thomas
https://bz.apache.org/bugzilla/show_bug.cgi?id=58626
--- Comment #16 from Mark Thomas ---
Created attachment 33883
--> https://bz.apache.org/bugzilla/attachment.cgi?id=33883&action=edit
Proposed patch for Tomcat 9.0.x, version 1
I don't have an HP-UX box to test with but the described behaviou
-native-trunk/native]
-
make[1]: Entering directory
`/srv/gump/public/workspace/tomcat-native-trunk/native'
/bin/bash /srv/gump/public/workspace/apr-1/dest-20160524/build-1/libtool
--silent --mode=compile gcc -g -O2 -pthread -DHAVE_CONFIG_H -DLINUX
-D_REENTRA
https://bz.apache.org/bugzilla/show_bug.cgi?id=59627
--- Comment #2 from Mark Thomas ---
There is another reason this issue is invalid. It can only happen with a
malicious client.
A normal client will never connect to a server while sending a host header for
something that it can't resolve to an
https://bz.apache.org/bugzilla/show_bug.cgi?id=59627
Remy Maucherat changed:
What|Removed |Added
Resolution|--- |INVALID
Status|NEW
https://bz.apache.org/bugzilla/show_bug.cgi?id=59627
dhardik...@gmail.com changed:
What|Removed |Added
CC||dhardik...@gmail.com
--
You are
https://bz.apache.org/bugzilla/show_bug.cgi?id=59627
Bug ID: 59627
Summary: request.getRequestURL() does not check if host header
value is a valid hostname format
Product: Tomcat 7
Version: unspecified
Hardware: PC
https://bz.apache.org/bugzilla/show_bug.cgi?id=58722
Mark Thomas changed:
What|Removed |Added
Resolution|--- |WONTFIX
Status|NEW
TL;DR
If you use remote JMX, you need to update your JVM to address CVE-2016-3427
For the longer version, see the blog post I just published on this:
http://engineering.pivotal.io/post/java-deserialization-jmx/
Mark
-
To unsubsc
Author: remm
Date: Tue May 24 09:26:00 2016
New Revision: 1745337
URL: http://svn.apache.org/viewvc?rev=1745337&view=rev
Log:
Checkstyle.
Modified:
tomcat/trunk/webapps/docs/changelog.xml
tomcat/trunk/webapps/docs/ssl-howto.xml
Modified: tomcat/trunk/webapps/docs/changelog.xml
URL:
http
lic/workspace/apache-commons/beanutils/dist/commons-beanutils-20160524.jar:/srv/gump/packages/commons-collections3/commons-collections-3.2.1.jar:/srv/gump/public/workspace/apache-commons/cli/target/commons-cli-1.4-SNAPSHOT.jar:/srv/gump/public/workspace/commons-lang-trunk/target/commons-lang3-3.5-SNAPS
18 matches
Mail list logo