-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Pascal,
On 6/25/15 10:01 AM, Christopher Schultz wrote: > Pascal, > > On 6/24/15 4:23 PM, Pascal Abaziou wrote: >> Hello, > >> I’m searching for the version that fixes a bug I’ve on a tomcat >> 6.0.24 (on redhat). As I do not reproduce it on my windows >> workstation with tomcat 6.0.44, I need elements to argue to >> upgrade to the sys admin. > >> So the bug : with a REST resource service implemented with >> Jersey, if there’s no method corresponding to a URI (under the >> hierarchy that Jersey should handle), Jersey raises a 404 >> NOT_FOUND error. > >> In 6.0.24, tomcat raises a 500 internal error. In 6.0.44, tomcat >> propagates the 404 not found error. > >> As the sysadmin want to stay on version delivered by redhead, I >> need elements to motivate an update. > >> I’ve read the tomcat 6 changelog, but did not find when this was >> fixed. > > This is more compelling reading: > > http://tomcat.apache.org/security-6.html Here are some issues you may want to specifically be aware of (search for them in the text of the above document): CVE-2012-0022 CVE-2012-4534 CVE-2012-2733 CVE-2012-3544/CVE-2013-4322 CVE-2005-2090/CVE-2013-4286 CVE-2014-0099 CVE-2014-0075 CVE-2014-0227 - -chris -----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org iQIcBAEBCAAGBQJVjA07AAoJEBzwKT+lPKRY3/wP/0AryA0WY6uek7TLhNg/G+dT hSFoVPNohDsKde2BP+kdCabBRVUnqe2b5rRID0CuGQe4Ve5RCzdmwQtXoJEvySNW WEiQVIKO4sg3D3ihrAAyDtWKKSwlHr8PY9R+J80yPATfKKdGjvAJkRMe1CxCGbZ9 hcU3F7g86h7dnqh2nL3EcfscCT/4E+0QXmrEaNWluMD2acCYFcfJRVzLpo+vTP7B exrOdlgPp4TWPt/StzoDIrJ00daI6y0rYtgQSNrKIXFGVgCB7PsEpDQoQ2fcLHkD QVUl5EfAIP4/oWSnLjh7Ncj2x/gp15yc3oR/EkBNgeqxVPzB+y0UHTrn7p6CzlED bVxFzOCdBCFHGqIuZi1hR26TIbHOu3XJlBBafpVD2kxJnKgyo5mjpxj/mMNVwX2A Wj/NHtmieKMRIqTKlqXyIFEYBBrzYVNNjRPmIR/ghPwGRntw45x2eEuzZLL49f1O NXIwiuf80H5pjrmMt/dWztRlq5QlyqFtxf/xMSNtWu1tnfG6OJI2Nsmtc1MCCXmu apZx3Em+lohCEh9/ElX8ZlKGJ2AsjhI6WNXvcS3uE7/8zInCU/P04y+QI9Zw/w/F jQAJ4gSarQAyk+hDKtSHcC2LfeExhbRR9upONF/P3wPOZukWN/T6ZJsMelhpzx/m /aJbYhiVNM9fmo6bfLww =ywXV -----END PGP SIGNATURE----- --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional commands, e-mail: users-h...@tomcat.apache.org