tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Christopher Schultz <ch...@christopherschultz.net>
Subject Re: AW: Question concerning mod_jk Security Fix CVE-2014-8111
Date Tue, 11 Aug 2015 19:03:29 GMT
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Chinoy,

On 8/8/15 10:47 AM, Chinoy Gupta wrote:
> Is the trunk stable?

Fairly. But there is a tag for 1.2.41 if you'd rather use that. It's
not yet an official ASF release, though.

- -chris

> On Sat, Aug 08, 2015 at 5:42 pm, Christopher Schultz
> <chris@christopherschultz.net<mailto:chris@christopherschultz.net>>
> wrote:
> 
> 
> Chinoy,
> 
> On 8/5/15 4:39 AM, Chinoy Gupta wrote:
>> When can we expect the release of JK 1.2.41 source code?
> 
> Well, you can get your hands on it right now: svn trunk is always 
> available.
> 
> Or you can wait for the vote to finish... I believe we have 3 votes
> to release.
> 
> http://tomcat.markmail.org/thread/evury5r6rwcls5df
> 
> -chris
> 
>> -----Original Message----- From: Mark Thomas 
>> [mailto:markt@apache.org] Sent: Sunday, July 26, 2015 10:16 PM
>> To: Tomcat Users List <users@tomcat.apache.org> Subject: Re: AW: 
>> Question concerning mod_jk Security Fix CVE-2014-8111
> 
>> On 20/07/2015 10:58, Kreuser, Peter wrote:
> 
>> <snip/>
> 
>>> Hi Mark,
>>> 
>>> I appreciate your open comment and that clarifies the lengthy 
>>> wait. I trust that now the solution gets going and will be
>>> solved soonish.
>>> 
>>> I'm in no position to criticize any wrongdoing on this CVE. I 
>>> only hope to find a clearer communication on the
>>> tomcat-security sites in the future and if THAT is RedHat's
>>> fault, then please clean up the process with them.
> 
>> I've just updated the JK security page on the Tomcat web site.
> 
>> To be clear, keeping this page up to date is entire the 
>> responsibility of the Tomcat committers. We dropped the ball on 
>> this one. That said, I had hoped - much like I hoped with the 
>> release - that RedHat would have directed one of their employees 
>> who is a committer to do the update. When that didn't happen
>> pretty much immediately, we (the Tomcat committers) should have
>> done it.
> 
>> I've read through the release docs and I should be able to get a 
>> 1.2.41 source release out. I'm planning on doing that next.
>> Binary releases are going to have to wait for other folks to
>> contribute them.
> 
>> Cheers,
> 
>> Mark
> 
>>> Thank You. Best regards,
>>> 
>>> Peter
>>> 
>>> PS: is that the correct position to add my response?
> 
>> Yes, it was.
> 
>> ---------------------------------------------------------------------
>
>> 
> 
> To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
>> For additional commands, e-mail: users-help@tomcat.apache.org
> 
> 
>> ---------------------------------------------------------------------
>
>> 
> 
> To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
>> For additional commands, e-mail: users-help@tomcat.apache.org
> 
> 
> ---------------------------------------------------------------------
>
> 
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
> For additional commands, e-mail: users-help@tomcat.apache.org
> 
> 
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - http://gpgtools.org

iQIcBAEBCAAGBQJVykcAAAoJEBzwKT+lPKRYCcwP/3VYNR7MjvEre/is4R3X4nIS
WXyXLTDZv17XiHnmKqO6xxvVmZmApYyhnbAotoTpWuruvreundZSBWG/b/EBn9vM
pujHrh3H1fbgTND8m8uw93TAQDuZC9j4WpYWtM4Wi8GiSl56eMMKDdpCI1Qizm3m
3JFXH1J7Ae2GDCfqcs99k1CNAhaUM4vuhifWC4QDCv1LOpimw9zgeIsGkvBGjpeQ
foxsSScs9c7HNHG4YrBn4kUmpAoxjotZuFfdytVHw9DvhXrLekNey/Me12ScO+H2
wYX7BDgUy5bP1C79Oa4ZmQdakIK8AADOxvZ8r2HCz0HP7yfTcJlBS38OyEY/ydZo
RM6cbgub1gcz5G4MIzCtC4u3auHuseY4jf4I08UH+BIeXCfLhvjlMKwGs4x0gsue
xvDG6HGrC57kcrI5XEy9EqtP4EWC4Jf02qDVP5D0ZC1a8QpFif959wek4ggsrXPJ
sLuX9NH1iIujhwueKRFLMUXepDUrMHMaEulm5bq3ooujuxymkoCjZgSnjtP2HH2b
sbaD5YpZEFGmxkNSGALM/qJ7s7VQxASmy8Ts/xvJrDrythRbUScBp4F+ht6dbpKz
HOShn1G6O/VnhvqaFdjM1l0cz90GMJD+jgoRILELRBbAToVSdnXtGhyy6zcxQZoA
44ykdrhWQrf0mWkmB0Vr
=n7w0
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org


Mime
View raw message