[Bug 61369] Tomcat 8.5.16 vulnerable to CVE-2016-0793

2017-08-02 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61369 --- Comment #5 from Christopher Schultz --- (In reply to Mark Thomas from comment #3) > The canonical path check is still required to enforce the required case > sensitivity. > > The Window APIs, most likely for reasons dating back to how 8.3

[Bug 61369] Tomcat 8.5.16 vulnerable to CVE-2016-0793

2017-08-02 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61369 Brett Schoppert changed: What|Removed |Added Resolution|--- |INVALID Status|NEEDINFO

[Bug 61369] Tomcat 8.5.16 vulnerable to CVE-2016-0793

2017-08-02 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61369 Mark Thomas changed: What|Removed |Added Status|NEW |NEEDINFO --- Comment #3 from Mark Thomas

[Bug 61369] Tomcat 8.5.16 vulnerable to CVE-2016-0793

2017-08-02 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61369 --- Comment #2 from Remy Maucherat --- The canonical path comparison is a last resort safety net. So it's still useful then, that's interesting. If you confirm the behavior, it seems we're good as is, the check is supposed to catch this and pre

[Bug 61369] Tomcat 8.5.16 vulnerable to CVE-2016-0793

2017-08-02 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61369 Svetlin Zarev changed: What|Removed |Added CC||svetlin.za...@abv.bg -- You are recei

[Bug 61369] Tomcat 8.5.16 vulnerable to CVE-2016-0793

2017-08-02 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61369 Mark Thomas changed: What|Removed |Added OS||All --- Comment #1 from Mark Thomas ---

[Bug 61369] Tomcat 8.5.16 vulnerable to CVE-2016-0793

2017-08-01 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61369 Brett Schoppert changed: What|Removed |Added OS||Windows Server 2012 -- You are rece