tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From James House <james.ho...@medibuy.com>
Subject Patch for Tomcat 3.1 - Shutdown Security Hole (Tomcat Killer)
Date Fri, 06 Oct 2000 17:16:05 GMT

Since this new find is a big security risk, I've made a patch available for
it.

You can download it (and other Tomcat 3.1 patches I've made) at the
following URL:

http://www.interobjective.com/tomcat/tomcatPatches.html

My other patches include:  

Fix for "recursive JSP include" bug.
Fix for insecure session Ids.

James


Mime
View raw message