Re: Vulnerability Remediation

2011-11-04 Thread Konstantin Kolinko
2011/11/5 Brendan P Keenan : > > It has been identified to me by our security group that my Apache Tomcat > 6.0.33 has the following vulnerability CVE-2011-3190. There is a link on > the Apache Tomcat 6.0 Security page to > http://svn.apache.org/viewvc?view=revision&revision=1162959 as a patch. > >

Re: Vulnerability Remediation

2011-11-04 Thread Daniel Mikusa
Brendan, The link is a list of the files that were modified to fix the vulnerability. These files can be used to patch the source code for Tomcat. After patching the source code, you would then need to recompile it and update your Tomcat installation with the recompiled binaries. In my opinion,

Vulnerability Remediation

2011-11-04 Thread Brendan P Keenan
It has been identified to me by our security group that my Apache Tomcat 6.0.33 has the following vulnerability CVE-2011-3190. There is a link on the Apache Tomcat 6.0 Security page to http://svn.apache.org/viewvc?view=revision&revision=1162959 as a patch. The link list three files: /tomcat/tc6.