Re: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-14 Thread Gomez Henri
> Sorry, I thought that got answered. Yes, Nacho give me the answer a little time later ;-) Thanks to him since I was afraid to have broken something. > Sounds good! Thanks, prepare room on the server ;-)

Re: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-14 Thread Craig R. McClanahan
Gomez Henri wrote: > I've asked some days ago about the 'Attic ?'... > Sorry, I thought that got answered. The "attic" is CVS's way of dealing with files that are on one branch of a repository, but not another -- or cases where you deleted a file, but you might want to go back to a previously t

Re: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-14 Thread Gomez Henri
> This raises an interesting policy issue that should be discussed. > In short, I think that packaging additional docs and fixes with your > 3.2.1 RPMs > is very misleading to Tomcat users, because what you get is *not* the > same as > what the "official" packages contain. I've added ajp13 multi

Re: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-14 Thread Craig R. McClanahan
GOMEZ Henri wrote: > >* This release fixes ***only*** the identified security > >vulnerabilities. > > It does not address any of the other bugs, or feature > >requests, related > > to Tomcat 3.2 final. These issues will be dealt with in future > > maintenance releases of Tomcat 3.2 as appropr

RE: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-14 Thread GOMEZ Henri
>* This release fixes ***only*** the identified security >vulnerabilities. > It does not address any of the other bugs, or feature >requests, related > to Tomcat 3.2 final. These issues will be dealt with in future > maintenance releases of Tomcat 3.2 as appropriate. > Not totally true sinc

Re: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-13 Thread Horace Vallas
het Craig - sorry to be dense - but what are the "appropriate contents" that should be replaced by 3.2.1? Is this just the various jar's in /lib? -- Wishing you an "OOBA OOBA" Y2K Horace...once known as "Kicker" :-) =

Re: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-12 Thread Craig R. McClanahan
Aron Kramlik wrote: > Has there been a definitive list of these security problems with > TC 3.1 or TC 3.2? > The definitive lists of what vulnerabilities were fixed are in the release notes document for each version (file "doc/readme" in the download). Subscribers to TOMCAT-DEV also saw the CVS

RE: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-12 Thread Aron Kramlik
PROTECTED]] Sent: Tuesday, December 12, 2000 4:32 PM To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED] Subject: [ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1 Recent investigations and reports have revealed security vulnerabilities in both Tomc

[ANNOUNCEMENT] Security Related Updates - Tomcat 3.1.1 and Tomcat 3.2.1

2000-12-12 Thread Craig R. McClanahan
Recent investigations and reports have revealed security vulnerabilities in both Tomcat 3.1 and Tomcat 3.2 final releases. To deal with these problems, the Tomcat team has developed maintenance releases, and recommended actions, for each major version. (Tomcat 4.0 milestone 4 shares one of these