Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-24 Thread Ian Darwin
On September 23, 2002 10:04 am, Remy Maucherat wrote: A security vulnerability which affects all releases of Tomcat 4.x has been discovered. It is proposed that new Tomcat 4.0.x and 4.1.x releases are made, at which time the exploit will be publicized. The security advisory will also

[VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Remy Maucherat
A security vulnerability which affects all releases of Tomcat 4.x has been discovered. It is proposed that new Tomcat 4.0.x and 4.1.x releases are made, at which time the exploit will be publicized. The security advisory will also include an easy workaround to protect existing Tomcat

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Henri Gomez
Tomcat 4.0.5 is virtually indentical to 4.0.4, with the exception of: - a bugfix to URL parsing - the security fix ballot +1 [+1] Yes, I approve this release -1 [ ] No, because: /ballot Which JTC should be used ? Tomcat 4.1.12 Stable release Tomcat

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Glenn Nielsen
Remy Maucherat wrote: A security vulnerability which affects all releases of Tomcat 4.x has been discovered. It is proposed that new Tomcat 4.0.x and 4.1.x releases are made, at which time the exploit will be publicized. The security advisory will also include an easy workaround to

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Jean-Francois Arcand
Remy Maucherat wrote: A security vulnerability which affects all releases of Tomcat 4.x has been discovered. It is proposed that new Tomcat 4.0.x and 4.1.x releases are made, at which time the exploit will be publicized. The security advisory will also include an easy workaround to

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Remy Maucherat
Henri Gomez wrote: Tomcat 4.0.5 is virtually indentical to 4.0.4, with the exception of: - a bugfix to URL parsing - the security fix ballot +1 [+1] Yes, I approve this release -1 [ ] No, because: /ballot Which JTC should be used ? I bundled the latest JTC binaries for Coyote

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Patrick Luby
Remy, Here's my votes. Patrick Tomcat 4.0.5 release ballot +1 [X] Yes, I approve this release -1 [ ] No, because: /ballot Tomcat 4.1.12 Stable release ballot +1 [X] Yes, I approve this release -1 [ ] No, because: /ballot --

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Henri Gomez
Remy Maucherat wrote: Henri Gomez wrote: Tomcat 4.0.5 is virtually indentical to 4.0.4, with the exception of: - a bugfix to URL parsing - the security fix ballot +1 [+1] Yes, I approve this release -1 [ ] No, because: /ballot Which JTC should be used ? I bundled the latest

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Amy Roh
Tomcat 4.0.5 release Tomcat 4.0.5 is virtually indentical to 4.0.4, with the exception of: - a bugfix to URL parsing - the security fix ballot +1 [X] Yes, I approve this release -1 [ ] No, because: /ballot Tomcat 4.1.12 Stable release

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Costin Manolache
Remy Maucherat wrote: A security vulnerability which affects all releases of Tomcat 4.x has been discovered. It is proposed that new Tomcat 4.0.x and 4.1.x releases are made, at which time the exploit will be publicized. The security advisory will also include an easy workaround to

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Bill Barker
- Original Message - From: Remy Maucherat [EMAIL PROTECTED] To: Tomcat Developers List [EMAIL PROTECTED] Sent: Monday, September 23, 2002 7:04 AM Subject: [VOTE] [4.0.5] [4.1.12] Security releases A security vulnerability which affects all releases of Tomcat 4.x has been discovered

RE: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Larry Isaacs
-Original Message- From: Remy Maucherat [mailto:[EMAIL PROTECTED]] Sent: Monday, September 23, 2002 10:05 AM To: Tomcat Developers List Subject: [VOTE] [4.0.5] [4.1.12] Security releases A security vulnerability which affects all releases of Tomcat 4.x has been discovered

Re: [VOTE] [4.0.5] [4.1.12] Security releases

2002-09-23 Thread Denis Benoit
On Mon, 23 Sep 2002, Remy Maucherat wrote: Tomcat 4.0.5 release Tomcat 4.0.5 is virtually indentical to 4.0.4, with the exception of: - a bugfix to URL parsing - the security fix ballot +1 [X] Yes, I approve this release -1 [ ] No, because: /ballot Tomcat