Re: Host appBase vs. Context docBase

2016-10-07 Thread Igal @ Lucee.org
Suppose you tell us your Tomcat version. I'm using Tomcat 8.5.5 -- not sure how relevant that is since AFAIK this has not changed in years. It is highly unlikely that you want the name to be App1 Of course that my host name is not App1, that was to remove fluff and to keep only the relevant

RE: Host appBase vs. Context docBase

2016-10-07 Thread Caldarale, Charles R
> From: Igal @ Lucee.org [mailto:i...@lucee.org] > Subject: Host appBase vs. Context docBase > Suppose that I have an application at C:\WebApps\App1 Suppose you tell us your Tomcat version. > > > > > > > Both of the above are incorrect. It is highly unlikely that you want the

Host appBase vs. Context docBase

2016-10-07 Thread Igal @ Lucee.org
Hi, Suppose that I have an application at C:\WebApps\App1 Is it better to set it up as Host appBase (option 1) or as Context docBase with empty path (option 2): Thanks, Igal Sapir Lucee Core Developer Lucee.org

Re: CVE-2016-6808 Apache Tomcat JK ISAPI Connector buffer overflow

2016-10-07 Thread Konstantin Kolinko
2016-10-07 18:02 GMT+03:00 Markus Koschany : > Hello, > > the recent security announcement for Apache Tomcat JK (CVE-2016-6808) > mentions that only IIS/ISAPI specific code is vulnerable. This issue was > apparently fixed in [1]. The vulnerable code is in the > map_uri_to_worker_ext function which

CVE-2016-6808 Apache Tomcat JK ISAPI Connector buffer overflow

2016-10-07 Thread Markus Koschany
Hello, the recent security announcement for Apache Tomcat JK (CVE-2016-6808) mentions that only IIS/ISAPI specific code is vulnerable. This issue was apparently fixed in [1]. The vulnerable code is in the map_uri_to_worker_ext function which is used by the IIS, Apache 1.3 and Apache 2.0 implementa

Re: Is there a 6.0.x patch for CVE-2016-5388?

2016-10-07 Thread Violeta Georgieva
Hi, 2016-10-04 9:35 GMT+03:00 Vamsavardhana Reddy : > > Hi, > > Thanks for your reply. I meant to ask if Tomcat will be releasing a 6.0.x > version (say 6.0.46?) addressing this CVE. If yes, what time frame may I > expect this version out? For Tomcat 6.0.46 you can follow this [1]. Regards, Vi

RE: Getting a blank page in Tomcat 6.3

2016-10-07 Thread Christoph Nenning
> From: "Nagappan , Ganesh - IT- PLM - Bhuj" > To: Tomcat Users List , > Date: 06.10.2016 13:54 > Subject: RE: Getting a blank page in Tomcat 6.3 > > > > "-Original Message- > From: André Warnier (tomcat) [mailto:a...@ice-sa.com] > Sent: Thursday, October 06, 2016 4:28 PM > To: user