Re: Change in behavior of parsing Content-Type header since TC 7.0.27

2012-06-26 Thread Au, Leon
On 6/25/12 9:19 AM, "Au, Leon" wrote: >Hi, > >There was a recent change to how Tomcat handles the Content-Type response >header in order to address Bug #52811 >(https://issues.apache.org/bugzilla/show_bug.cgi?id=52811) > >We've noticed that this can cause

Change in behavior of parsing Content-Type header since TC 7.0.27

2012-06-25 Thread Au, Leon
Hi, There was a recent change to how Tomcat handles the Content-Type response header in order to address Bug #52811 (https://issues.apache.org/bugzilla/show_bug.cgi?id=52811) We've noticed that this can cause issues with client code when parsing the response. We traced the issue to that fact

Re: Want to confirm fix of a security vulnerability

2012-03-09 Thread Au, Leon
On 3/9/12 2:19 PM, "Jayant Sane" wrote: > > >Pardon the re-post but I just wanted some kind of ack from the Tomcat dev >team on the following. >Has the "Tomcat WAR deployment directory traversal..." issue as detailed >in http://securitytracker.com/id/1023504 been fixed in version 7.0.023? >As I m

Re: Tomcat suddenly dies

2012-02-27 Thread Au, Leon
On 2/27/12 5:32 PM, "Carl Kabbe" wrote: >I have run Tomcat in two environments and both produced the same results. > >Server 1: > >OS - Slackware Linux 13.x 64 bit >JVM - 1.6.0_31 >Tomcat - 6.0.24 > >Server memory 16GB >Heap 2GB, PermGen 300M > >Server 2: > >OS - Slackware 13.x 64 bit >JVM - 1.6.

Re: Question regarding mappings for CVE-2005-4836

2012-02-07 Thread Au, Leon
On 2/7/12 12:01 PM, "Christopher Restorff" wrote: >Hello, > >I have a question regarding CVE-2005-4836: >http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-4836 > >The security bulletin, http://tomcat.apache.org/security-4.html, >mentions that it will not be fixed in 4.x. However, there is