Return-Path: X-Original-To: apmail-tomcat-announce-archive@minotaur.apache.org Delivered-To: apmail-tomcat-announce-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 361C27D51 for ; Fri, 2 Sep 2011 08:53:28 +0000 (UTC) Received: (qmail 75245 invoked by uid 500); 2 Sep 2011 08:53:25 -0000 Delivered-To: apmail-tomcat-announce-archive@tomcat.apache.org Received: (qmail 74743 invoked by uid 500); 2 Sep 2011 08:53:06 -0000 Mailing-List: contact announce-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: announce@tomcat.apache.org Delivered-To: mailing list announce@tomcat.apache.org Delivered-To: moderator for announce@tomcat.apache.org Received: (qmail 69266 invoked by uid 99); 2 Sep 2011 08:51:43 -0000 Message-ID: <4E60991A.1080605@apache.org> Date: Fri, 02 Sep 2011 09:51:38 +0100 From: Mark Thomas User-Agent: Mozilla/5.0 (Windows NT 5.2; WOW64; rv:6.0.1) Gecko/20110830 Thunderbird/6.0.1 MIME-Version: 1.0 To: Tomcat Users List CC: Tomcat Announce List , Tomcat Developers List , announce@apache.org Subject: [ANN] Apache Tomcat 7.0.21 released X-Enigmail-Version: 1.3.1 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit The Apache Tomcat team announces the immediate availability of Apache Tomcat 7.0.21 Apache Tomcat 7.0.21 includes security fixes, bug fixes and new features compared to version 7.0.20 including: - A fix for CVE-2011-3190 that allowed an attacker to inject requests when Tomcat was configured behind a reverse proxy using the AJP protocol. - Multiple additions and improvements to the memory leak detection/prevention features. - Improved validation of received AJP messages. Please refer to the change log for the complete list of changes: http://tomcat.apache.org/tomcat-7.0-doc/changelog.html Note that this version has 4 zip binaries: a generic one and three bundled with Tomcat native binaries for Windows operating systems running on different CPU architectures. Downloads: http://tomcat.apache.org/download-70.cgi Migration guide from Apache Tomcat 5.5.x and 6.0.x: http://tomcat.apache.org/migration.html Thank you, -- The Apache Tomcat Team