Re: [SECURITY] CVE-2008-1947: Tomcat host-manager XSS vulnerability

2008-07-14 Thread Mark Thomas
Eric Hawkes wrote: Hi, This issue has been fixed ... in 5.5.27 and 6.0.17. It is anticipated that these versions will be released shortly. It's been about six weeks. Is there any further information on when Tomcat 5.5.27 will be released? Thanks, Eric No plans as yet. From past exp

RE: [SECURITY] CVE-2008-1947: Tomcat host-manager XSS vulnerability

2008-07-14 Thread Eric Hawkes
Hi, > This issue has been fixed ... in 5.5.27 and 6.0.17. > It is anticipated that these versions will be released shortly. It's been about six weeks. Is there any further information on when Tomcat 5.5.27 will be released? Thanks, Eric -Original Message- From: Mark Thomas [