Re: CVE-2014-0160

2014-04-10 Thread Andrew Carr
Thanks for the response, both of you. On Thu, Apr 10, 2014 at 4:30 AM, Christopher Schultz < ch...@christopherschultz.net> wrote: > Andrew, > > On 4/8/14, 5:43 PM, Andrew Carr wrote: > > http://www.openssl.org/news/secadv_20140407.txt > > > > Hi Tomcat Devs, > > > > I have been on the dev list f

Re: CVE-2014-0160

2014-04-10 Thread Christopher Schultz
Andrew, On 4/8/14, 5:43 PM, Andrew Carr wrote: > http://www.openssl.org/news/secadv_20140407.txt > > Hi Tomcat Devs, > > I have been on the dev list for a few years, and a tomcat developer longer > than that. While I haven't contributed yet, I was curious if this cve > needs a contribution. As

Re: CVE-2014-0160

2014-04-09 Thread Mladen Turk
On 04/09/2014 01:43 AM, Andrew Carr wrote: http://www.openssl.org/news/secadv_20140407.txt Hi Tomcat Devs, I have been on the dev list for a few years, and a tomcat developer longer than that. While I haven't contributed yet, I was curious if this cve needs a contribution. As far as I can tel

CVE-2014-0160

2014-04-08 Thread Andrew Carr
http://www.openssl.org/news/secadv_20140407.txt Hi Tomcat Devs, I have been on the dev list for a few years, and a tomcat developer longer than that. While I haven't contributed yet, I was curious if this cve needs a contribution. As far as I can tell, if you recompile your native libs with the