Re: Is Tomcat 7.0.62 vulnerable to these issues: CVE-2007-6750/CVE-2009-5111

2015-06-25 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Mark, On 6/25/15 3:49 AM, Mark Thomas wrote: > On 25/06/2015 07:07, Nikitha Benny wrote: >> Hi, >> >> I am confused regarding the 2 security issues CVE-2007-6750 and >> CVE-2009-5111. >> >> Can they be tracked to CVE-2012-5568? > > All of those C

Re: Is Tomcat 7.0.62 vulnerable to these issues: CVE-2007-6750/CVE-2009-5111

2015-06-25 Thread Mark Thomas
On 25/06/2015 07:07, Nikitha Benny wrote: > Hi, > > I am confused regarding the 2 security issues CVE-2007-6750 > and CVE-2009-5111. > > Can they be tracked to CVE-2012-5568? All of those CVEs are essentially the same issue (slowloris) in different products. > According to CVE-2012-5568, I und

Is Tomcat 7.0.62 vulnerable to these issues: CVE-2007-6750/CVE-2009-5111

2015-06-24 Thread Nikitha Benny
Hi, I am confused regarding the 2 security issues CVE-2007-6750 and CVE-2009-5111. Can they be tracked to CVE-2012-5568? According to CVE-2012-5568, I understand that this is not a vulnerability in Tomcat. Please confirm. When Tomcat 7.0.62 was scanned using McAfee Vulnerability Manager Tool, i