Re: Impact of tomcat CVE-2012-4534

2012-12-06 Thread Chiradeep Vittal
You mean tomcat 7? Not sure. I haven't tried it. Anybody else tried tomcat7? On 12/5/12 7:26 PM, "Gavin Lee" wrote: >So besides 6.0.35, the other higher version also has this issue? > >On Thu, Dec 6, 2012 at 2:50 AM, Chiradeep Vittal > wrote: >> Versions higher than 6.0.33 have problems with cla

Re: Impact of tomcat CVE-2012-4534

2012-12-05 Thread Gavin Lee
So besides 6.0.35, the other higher version also has this issue? On Thu, Dec 6, 2012 at 2:50 AM, Chiradeep Vittal wrote: > Versions higher than 6.0.33 have problems with classloading the MySQL > driver. > > On 12/5/12 6:20 AM, "Gavin Lee" wrote: > >>This vulnerability possibly causes denial of s

Re: Impact of tomcat CVE-2012-4534

2012-12-05 Thread Chiradeep Vittal
Versions higher than 6.0.33 have problems with classloading the MySQL driver. On 12/5/12 6:20 AM, "Gavin Lee" wrote: >This vulnerability possibly causes denial of service. >See below link: >http://mail-archives.apache.org/mod_mbox/www-announce/201212.mbox/%3C50BE5 >35a.9000...@apache.org%3E > >I

RE: Impact of tomcat CVE-2012-4534

2012-12-05 Thread Mice Xia
These two are probably not very critical, but if possible, it's valuable to add a regular security scan job. Regards Mice -Original Message- From: Gavin Lee [mailto:gavin@gmail.com] Sent: Wednesday, December 05, 2012 10:20 PM To: cloudstack Subject: Impact of tomcat CVE-2012-