Re: [SECURITY] CVE-2008-5519: Apache Tomcat mod_jk information disclosure vulnerability

2009-04-17 Thread Jakob Ericsson
Hi, We are also getting this error in mod_proxy_ajp (2.2.11 on Windows) Anyone know if this is the same fix? https://issues.apache.org/bugzilla/show_bug.cgi?id=46949 Seems to be fixed. /Jakob On Tue, Apr 7, 2009 at 10:42 PM, Mark Thomas ma...@apache.org wrote: -BEGIN PGP SIGNED

Re: [SECURITY] CVE-2008-5519: Apache Tomcat mod_jk information disclosure vulnerability

2009-04-17 Thread Rainer Jung
Hi, the problem is not fixed in httpd 2.2.11. It will be fixed in 2.2.12. A source patch is available under the URL http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/ I assume, that you don't build yourself, because most Windows httpd users start with a binary download. There is no

[SECURITY] CVE-2008-5519: Apache Tomcat mod_jk information disclosure vulnerability

2009-04-07 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Vulnerability announcement: CVE-2008-5519: Apache Tomcat mod_jk information disclosure vulnerability Severity: important Vendor: The Apache Software Foundation Versions Affected: mod_jk 1.2.0 to 1.2.26 Description: Situations where faulty clients