Re: Changes to get tomcat8 security fixes into Debian 9?

2020-03-06 Thread Thorsten Glaser
On Fri, 6 Mar 2020, Markus Koschany wrote: > Please note that the AJP connector is disabled by default in Debian and That being said, it’s the first thing we enable as AJP together with mod_jk is the only reliable method I found to use Tomcat with Apache. Just please don’t discount it entirely.

Re: Changes to get tomcat8 security fixes into Debian 9?

2020-03-06 Thread Andreas Tille
On Fri, Mar 06, 2020 at 12:24:56AM +0100, Markus Koschany wrote: > Hi Andreas, > > Am 05.03.20 um 09:34 schrieb Andreas Tille: > > Hi, > > > > I was wondering, whether there is a chance to get CVE-2020-1938 fixed in > > Tomcat8 in Stretch? If the chances are low possibly backporting Tomcat9 > >