Re: [SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat

2014-09-10 Thread Mark Thomas
ou...@tomcat.apache.org; fulldisclos...@seclists.org; >> bugt...@securityfocus.com >> Subject: [SECURITY] CVE-2013- Remote Code Execution in Apache >> Tomcat >> > CVE-2013- Remote Code Execution > > Severity: Important > > Vendor: The Apache Software Foundation

Re: [SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat

2014-09-10 Thread David kerber
...@securityfocus.com Subject: [SECURITY] CVE-2013- Remote Code Execution in Apache Tomcat -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013- Remote Code Execution Severity: Important Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 7.0.0 to 7.0.39

RE: [SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat

2014-09-10 Thread Jeffrey Janner
tyfocus.com > Subject: [SECURITY] CVE-2013-4444 Remote Code Execution in Apache > Tomcat > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > CVE-2013- Remote Code Execution > > Severity: Important > > Vendor: The Apache Software Foundation >

[SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat

2014-09-10 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013- Remote Code Execution Severity: Important Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 7.0.0 to 7.0.39 Description: In very limited circumstances, it was possible for an attacker to upload a malicious JS