Re: [ANNOUNCEMENT] Tomcat 4.0.3 security hotfix release

2002-03-01 Thread Remy Maucherat
> Remy Maucherat wrote: > > > > A security vulnerability affecting the sandboxing provided by the Java > > Security Manager has been discovered. The request dipatcher functionality of > > the Servlet API could be used by a malicious servlet or JSP page to get > > access to any resource located on

[ANNOUNCEMENT] Tomcat 4.0.3 security hotfix release

2002-03-01 Thread Remy Maucherat
A security vulnerability affecting the sandboxing provided by the Java Security Manager has been discovered. The request dipatcher functionality of the Servlet API could be used by a malicious servlet or JSP page to get access to any resource located on the server's filesystem, bypassing the Secur