Re: [Full-disclosure] [SECURITY] CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure

2011-09-07 Thread Henri Salo
On Wed, Aug 31, 2011 at 01:22:51PM +0300, Henri Salo wrote: > On Mon, Aug 29, 2011 at 08:52:00PM +0100, Mark Thomas wrote: > > CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure > > > > Severity: Important > > > > Vendor: The Apache Software Foundation > > > > Versions

Re: [Full-disclosure] [SECURITY] CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure

2011-08-31 Thread Henri Salo
On Mon, Aug 29, 2011 at 08:52:00PM +0100, Mark Thomas wrote: > CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure > > Severity: Important > > Vendor: The Apache Software Foundation > > Versions Affected: > - Tomcat 7.0.0 to 7.0.20 > - Tomcat 6.0.0 to 6.0.33 > - Tomcat 5

[Full-disclosure] [SECURITY] CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure

2011-08-29 Thread Mark Thomas
CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure Severity: Important Vendor: The Apache Software Foundation Versions Affected: - Tomcat 7.0.0 to 7.0.20 - Tomcat 6.0.0 to 6.0.33 - Tomcat 5.5.0 to 5.5.33 - Earlier, unsupported versions may also be affected Description: