Re: About CVE-2015-5345

2016-12-08 Thread Mark Thomas
On 08/12/2016 09:54, Emmanuel Bourg wrote: > [resending as a new message instead of a reply, sorry] Thanks. > I'm still working on the security backports in Debian and I have a > question regarding CVE-2015-5345. On the Tomcat 7 security page the > commits 1715213 and 1717212 are referenced. If I

About CVE-2015-5345

2016-12-08 Thread Emmanuel Bourg
[resending as a new message instead of a reply, sorry] Hi all, I'm still working on the security backports in Debian and I have a question regarding CVE-2015-5345. On the Tomcat 7 security page the commits 1715213 and 1717212 are referenced. If I'm not mistaken the commit 1716860 should also be p

About CVE-2015-5345

2016-12-08 Thread Emmanuel Bourg
Hi all, I'm still working on the security backports in Debian and I have a question regarding CVE-2015-5345. On the Tomcat 7 security page the commits 1715213 and 1717212 are referenced. If I'm not mistaken the commit 1716860 should also be part of the fix, otherwise the mapper*RedirectEnabled att