Re: [SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat

2014-09-10 Thread Mark Thomas
On 10/09/2014 16:10, Jeffrey Janner wrote: >> -Original Message- >> From: Mark Thomas [mailto:ma...@apache.org] >> Sent: Wednesday, September 10, 2014 9:00 AM >> To: Tomcat Users List >> Cc: Tomcat Developers List; annou...@apache.org; >> annou...@tomcat.apache.org; fulldisclos...@seclists.

Re: [SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat

2014-09-10 Thread David kerber
On 9/10/2014 11:10 AM, Jeffrey Janner wrote: -Original Message- From: Mark Thomas [mailto:ma...@apache.org] Sent: Wednesday, September 10, 2014 9:00 AM To: Tomcat Users List Cc: Tomcat Developers List; annou...@apache.org; annou...@tomcat.apache.org; fulldisclos...@seclists.org; bugt...@s

RE: [SECURITY] CVE-2013-4444 Remote Code Execution in Apache Tomcat

2014-09-10 Thread Jeffrey Janner
> -Original Message- > From: Mark Thomas [mailto:ma...@apache.org] > Sent: Wednesday, September 10, 2014 9:00 AM > To: Tomcat Users List > Cc: Tomcat Developers List; annou...@apache.org; > annou...@tomcat.apache.org; fulldisclos...@seclists.org; > bugt...@securityfocus.com > Subject: [SECU