Question about a known security vulnerability

2012-03-08 Thread Jayant Sane
Hello,  This is in regard to the security vulnerability "Tomcat WAR Deployment Directory Traversal Flaw May Cause Files to Be Deleted" as detailed in  http://securitytracker.com/id/1023504 Per the above, versions 5.5.0-5.5.28, 6.0.0-6.0.20 and possibly earlier versions were affected.  Question

Want to confirm fix of a security vulnerability

2012-03-09 Thread Jayant Sane
Pardon the re-post but I just wanted some kind of ack from the Tomcat dev team on the following.  Has the "Tomcat WAR deployment directory traversal..." issue as detailed in http://securitytracker.com/id/1023504 been fixed in version 7.0.023?  As I mentioned, the Apache security team wont comme