From users-return-227883-apmail-tomcat-users-archive=tomcat.apache.org@tomcat.apache.org Wed Sep 21 14:00:05 2011 Return-Path: X-Original-To: apmail-tomcat-users-archive@www.apache.org Delivered-To: apmail-tomcat-users-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 7026B9335 for ; Wed, 21 Sep 2011 14:00:05 +0000 (UTC) Received: (qmail 98529 invoked by uid 500); 21 Sep 2011 14:00:00 -0000 Delivered-To: apmail-tomcat-users-archive@tomcat.apache.org Received: (qmail 98362 invoked by uid 500); 21 Sep 2011 13:59:59 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 98353 invoked by uid 99); 21 Sep 2011 13:59:59 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 21 Sep 2011 13:59:59 +0000 X-ASF-Spam-Status: No, hits=0.7 required=5.0 tests=RCVD_IN_DNSWL_NONE,SPF_NEUTRAL X-Spam-Check-By: apache.org Received-SPF: neutral (athena.apache.org: local policy) Received: from [76.96.62.40] (HELO qmta04.westchester.pa.mail.comcast.net) (76.96.62.40) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 21 Sep 2011 13:59:52 +0000 Received: from omta17.westchester.pa.mail.comcast.net ([76.96.62.89]) by qmta04.westchester.pa.mail.comcast.net with comcast id bPaM1h0061vXlb854RzYY7; Wed, 21 Sep 2011 13:59:32 +0000 Received: from [192.168.1.201] ([69.143.109.145]) by omta17.westchester.pa.mail.comcast.net with comcast id bRzX1h01K38FjT13dRzYSV; Wed, 21 Sep 2011 13:59:32 +0000 Message-ID: <4E79EDC3.9060907@christopherschultz.net> Date: Wed, 21 Sep 2011 09:59:31 -0400 From: Christopher Schultz User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:6.0.2) Gecko/20110902 Thunderbird/6.0.2 MIME-Version: 1.0 To: Tomcat Users List Subject: Re: Availability of Apache Tomcat 6.0.34? References: <4E738802.8070403@christopherschultz.net> In-Reply-To: X-Enigmail-Version: 1.3.1 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Shanti, On 9/21/2011 1:39 AM, Yajnik, Shanti wrote: > Thanks Chris. Do you know when 6.0.34 version of Tomcat will be > available for download? Note that there is a simple workaround with affected versions: use mod_jk's "secret" setting on all your workers and on the JK connector in Tomcat and you should be safe from this attack. - -chris -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk557cMACgkQ9CaO5/Lv0PCGqwCgvlHcsgojgZa45yhkEgpIwgZQ vRcAn0YawIl3VQVAD7uabMLFxeVdj72T =jeZx -----END PGP SIGNATURE----- --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org