Re: Problem configuring a resource link after Fixed CVE-2016-6797

2016-12-23 Thread Per Newgro
Thanks alot. I will do. Cheers Per Am 22.12.2016 um 21:09 schrieb Coty Sutherland: It's possible that there was an imperfect patch released by Debian. Yep, they're missing r1763236 in wheezy; it was added to Jessie on 12/8 (commit 49e4e30b8c12ffc28378075545f413b725ad5cd9). Please notify your m

Re: Problem configuring a resource link after Fixed CVE-2016-6797

2016-12-22 Thread Coty Sutherland
> It's possible that there was an imperfect patch released by Debian. Yep, they're missing r1763236 in wheezy; it was added to Jessie on 12/8 (commit 49e4e30b8c12ffc28378075545f413b725ad5cd9). Please notify your maintainer to have it fixed :) On Thu, Dec 22, 2016 at 1:48 PM, Christopher Schultz

Re: Problem configuring a resource link after Fixed CVE-2016-6797

2016-12-22 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Per, On 12/22/16 11:45 AM, Per Newgro wrote: > no we don't see the same problems with a 7.0.64 installation. But > what can we do with our debian version. I think it shall be > possible to configure the datasource somehow. It's possible that there

Re: Problem configuring a resource link after Fixed CVE-2016-6797

2016-12-22 Thread Per Newgro
Hello, no we don't see the same problems with a 7.0.64 installation. But what can we do with our debian version. I think it shall be possible to configure the datasource somehow. Thanks Per On 16 December 2016 09:12:24 GMT+00:00, Per Newgro wrote: Hello, i've just updated my debian serve

Re: Problem configuring a resource link after Fixed CVE-2016-6797

2016-12-16 Thread Mark Thomas
On 16 December 2016 09:12:24 GMT+00:00, Per Newgro wrote: >Hello, > >i've just updated my debian server with a update for tomcat >7.0.28-4+deb7u6 to 7.0.28-4+deb7u7. Do you see the same problem with the latest 7.0.x obtained directly from the ASF? Mark > >In the release notes >(https://packag

Problem configuring a resource link after Fixed CVE-2016-6797

2016-12-16 Thread Per Newgro
Hello, i've just updated my debian server with a update for tomcat 7.0.28-4+deb7u6 to 7.0.28-4+deb7u7. In the release notes (https://packages.qa.debian.org/t/tomcat7/news/20161201T223017Z.html) i found > * Fixed CVE-2016-6797: The ResourceLinkFactory did not limit web application > acces