Re: Connection re-use bug in XML-RPC 3.1.3

2010-04-02 Thread Jochen Wiedmann
...@medstrat.com To: xmlrpc-a...@ws.apache.org Date: Thu, 18 Mar 2010 10:22:21 -0500 Subject: Connection re-use bug in XML-RPC 3.1.3 XML-RPC Developers, There is a security hole in the re-use of server connections when basic authentication is involved. Context: We have an XML-RPC client that connects

Re: Connection re-use bug in XML-RPC 3.1.3

2010-04-02 Thread Greg Smethells
-- From: Greg Smethells gsmethe...@medstrat.com To: xmlrpc-a...@ws.apache.org Date: Thu, 18 Mar 2010 10:22:21 -0500 Subject: Connection re-use bug in XML-RPC 3.1.3 XML-RPC Developers, There is a security hole in the re-use of server connections when basic authentication is involved