Re: Where's the fix of CVE-2005-2090?

2008-01-29 Thread Mark Thomas
Filip Hanik - Dev Lists wrote: Mark Thomas wrote: Michal Vyskocil wrote: I'm unable to locate a patch to fix the CVE-2005-2090. I cannot found any hint from svn commit log or bugzilla. Maybe is this commit r513079 | mark

Re: Where's the fix of CVE-2005-2090?

2008-01-29 Thread Michal Vyskocil
On Monday 28 January 2008 21:09:31 Mark Thomas wrote: > Michal Vyskocil wrote: > > I'm unable to locate a patch to fix the CVE-2005-2090. I cannot found any > > hint from svn commit log or bugzilla. > > > > Maybe is this commit > > ---

Re: Where's the fix of CVE-2005-2090?

2008-01-28 Thread Filip Hanik - Dev Lists
Mark Thomas wrote: Michal Vyskocil wrote: I'm unable to locate a patch to fix the CVE-2005-2090. I cannot found any hint from svn commit log or bugzilla. Maybe is this commit r513079 | markt | 2007-03-01 01:26:12 +0100 (Č

Re: Where's the fix of CVE-2005-2090?

2008-01-28 Thread Mark Thomas
Michal Vyskocil wrote: I'm unable to locate a patch to fix the CVE-2005-2090. I cannot found any hint from svn commit log or bugzilla. Maybe is this commit r513079 | markt | 2007-03-01 01:26:12 +0100 (Čt, 01 bře 2007) | 1

Where's the fix of CVE-2005-2090?

2008-01-28 Thread Michal Vyskocil
Hi, I'm unable to locate a patch to fix the CVE-2005-2090. I cannot found any hint from svn commit log or bugzilla. According http://tomcat.apache.org/security-5.html is this issue fixed in 5.5.23, so I've downloaded the 5.5.20 and a 5.5.23 from archive.apache.org and use a diff -ru on unpacke