On 3/9/12 2:19 PM, "Jayant Sane" <jayant_s...@hotmail.com> wrote:
> > >Pardon the re-post but I just wanted some kind of ack from the Tomcat dev >team on the following. >Has the "Tomcat WAR deployment directory traversal..." issue as detailed >in http://securitytracker.com/id/1023504 been fixed in version 7.0.023? >As I mentioned, the Apache security team wont comment on known security >issues. According to your link, only Tomcat major version 5 and 6 were affected. Also, the issue was report Jan 25, 2010. Tomcat 7.0.23 was released Nov 25, 2011. I imagine that any issue would have been patched well before that. http://tomcat.apache.org/tomcat-7.0-doc/changelog.html Leon > >many thanks,Jayant >--------------------------------------------------------------------- >To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org >For additional commands, e-mail: users-h...@tomcat.apache.org > --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional commands, e-mail: users-h...@tomcat.apache.org