Re: Incorporating changes and compiling Tomcat

2011-09-28 Thread Pid
On 27/09/2011 21:58, gilbert.be...@bcbssc.com wrote: Can any one please direct me to instructions on how to incorporate fixes and then recompile. Target OS is Windows Server 2003. Thanks! Note: Tomcat doesn't issue patches, a new version is released. Unless you are planning to write patches

RE: Incorporating changes and compiling Tomcat

2011-09-28 Thread Wilde, Bruce R.
: Incorporating changes and compiling Tomcat On 27/09/2011 21:58, gilbert.be...@bcbssc.com wrote: Can any one please direct me to instructions on how to incorporate fixes and then recompile. Target OS is Windows Server 2003. Thanks! Note: Tomcat doesn't issue patches, a new version is released

Re: Incorporating changes and compiling Tomcat

2011-09-28 Thread Konstantin Kolinko
2011/9/28 Wilde, Bruce R. bruce.r.wi...@saic.com: So, what are security minded system administrators to do about mitigating CVE-2011-3190 against V6.0.33? From the http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.34_( not_yet_released) page Mitigation options:        

RE: Incorporating changes and compiling Tomcat

2011-09-28 Thread GILBERT.BERRY
31873 (803) 466-7282 cell gilbert.be...@mytricare.com THIS EMAIL IS CONFIDENTIAL http://www.bcbssc.com/confidentiality.htm -Original Message- From: Pid [mailto:p...@pidster.com] Sent: Wednesday, September 28, 2011 1:34 PM To: Tomcat Users List Subject: Re: Incorporating changes

RE: Incorporating changes and compiling Tomcat

2011-09-28 Thread GILBERT.BERRY
Message- From: Konstantin Kolinko [mailto:knst.koli...@gmail.com] Sent: Wednesday, September 28, 2011 1:56 PM To: Tomcat Users List Subject: Re: Incorporating changes and compiling Tomcat 2011/9/28 Wilde, Bruce R. bruce.r.wi...@saic.com: So, what are security minded system administrators

Re: Incorporating changes and compiling Tomcat

2011-09-28 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Bruce, On 9/28/2011 1:44 PM, Wilde, Bruce R. wrote: So, what are security minded system administrators to do about mitigating CVE-2011-3190 against V6.0.33? This is the option I chose: (c) Configure both Tomcat and the reverse proxy to use a

Re: Incorporating changes and compiling Tomcat

2011-09-28 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Gilbert, On 9/28/2011 1:58 PM, gilbert.be...@bcbssc.com wrote: Unfortunately, the government won't let we wait. Maybe patches is the wrong word. For instance the updated code for AjpAprProcessor.java and AjpProcessor.java needed to fix

Re: Incorporating changes and compiling Tomcat

2011-09-28 Thread Pid
On 28/09/2011 18:44, Wilde, Bruce R. wrote: So, what are security minded system administrators to do about mitigating CVE-2011-3190 against V6.0.33? From the http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.34_( not_yet_released) page Mitigation options:

Re: Incorporating changes and compiling Tomcat

2011-09-27 Thread Konstantin Kolinko
2011/9/28 gilbert.be...@bcbssc.com: Can any one please direct me to instructions on how to incorporate fixes and then recompile.  Target OS is Windows Server 2003.  Thanks! RTFM? - To unsubscribe, e-mail:

Re: Incorporating changes and compiling Tomcat

2011-09-27 Thread Mark Eggers
- Original Message - From: gilbert.be...@bcbssc.com gilbert.be...@bcbssc.com To: users@tomcat.apache.org Cc: Sent: Tuesday, September 27, 2011 1:58 PM Subject: Incorporating changes and compiling Tomcat Can any one please direct me to instructions on how to incorporate fixes and