On 3/9/12 2:19 PM, "Jayant Sane" <jayant_s...@hotmail.com> wrote:

>
>
>Pardon the re-post but I just wanted some kind of ack from the Tomcat dev
>team on the following.
>Has the "Tomcat WAR deployment directory traversal..." issue as detailed
>in http://securitytracker.com/id/1023504 been fixed in version 7.0.023?
>As I mentioned, the Apache security team wont comment on known security
>issues. 

According to your link, only Tomcat major version 5 and 6 were affected.
Also, the issue was report Jan 25, 2010.  Tomcat 7.0.23 was released Nov
25, 2011.  I imagine that any issue would have been patched well before
that.

http://tomcat.apache.org/tomcat-7.0-doc/changelog.html

Leon

>
>many thanks,Jayant                                     
>---------------------------------------------------------------------
>To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
>For additional commands, e-mail: users-h...@tomcat.apache.org
>


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to