Re: EXTERNAL: Re: install of Tomcat 6.0.33

2011-10-10 Thread Pid
> -Original Message- > From: Christopher Schultz [mailto:ch...@christopherschultz.net] > Sent: Monday, October 10, 2011 4:38 PM > To: Tomcat Users List > Subject: EXTERNAL: Re: install of Tomcat 6.0.33 > > Anthony, > > On 10/10/2011 3:00 PM, Palmer, Anthony wrote: >>

RE: EXTERNAL: Re: install of Tomcat 6.0.33

2011-10-10 Thread Palmer, Anthony
Here is a response that I just received. What do you think? -Original Message- From: Christopher Schultz [mailto:ch...@christopherschultz.net] Sent: Monday, October 10, 2011 4:38 PM To: Tomcat Users List Subject: EXTERNAL: Re: install of Tomcat 6.0.33 -BEGIN PGP SIGNED MESSAGE

Re: install of Tomcat 6.0.33

2011-10-10 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Anthony, On 10/10/2011 3:00 PM, Palmer, Anthony wrote: > [...] most of the problems found tell us the same thing of how to > fix them which is to go to the next upgrade/update of Apache. So, you should upgrade to the latest version of Apache Tomcat (

Re: install of Tomcat 6.0.33

2011-10-10 Thread Palmer, Anthony
The version of Apache that is shown in JIRA is Apache Tomcat/6.0.20, I was told that this update was needed from foundstone after a recent scan was done. This is a 32-bit VM. Here are some the vulnarabilites that we found, but most of the problems found tell us the same thing of how to fix them

RE: EXTERNAL: Re: install of Tomcat 6.0.33

2011-10-10 Thread Palmer, Anthony
has released an update to address the issue: http://tomcat.apache.org/security-7.html -Original Message- From: Mark Thomas [mailto:ma...@apache.org] Sent: Monday, October 10, 2011 10:35 AM To: Tomcat Users List Subject: EXTERNAL: Re: install of Tomcat 6.0.33 On 10/10/2011 15:18, Pa

Re: install of Tomcat 6.0.33

2011-10-10 Thread Mark Thomas
On 10/10/2011 15:18, Palmer, Anthony wrote: > Hello, I am looking for documentation on doing a patch install. There is no documentation since the ASF does not release patches. Each release of Apache Tomcat is a full release. There is no mechanism to patch an older release to a newer one. There ar