diff options
author | Ernst de Haan <znerd@FreeBSD.org> | 2002-10-10 22:51:09 +0000 |
---|---|---|
committer | Ernst de Haan <znerd@FreeBSD.org> | 2002-10-10 22:51:09 +0000 |
commit | 2d0baff5f5c1f774deae58c891714c3749a0c7e7 (patch) | |
tree | 75399dda26bb3b3480733c494ebe13d85f759ff0 /www/Makefile | |
parent | 7cb93958e0062e091e80cb23a73cd48dfe7679cd (diff) | |
download | ports-2d0baff5f5c1f774deae58c891714c3749a0c7e7.tar.gz ports-2d0baff5f5c1f774deae58c891714c3749a0c7e7.zip |
Upgrade to Tomcat 4.0.6, released on 9 October 2002. From the
News & Status page:
A security vulnerability has been confirmed to exist in
Apache Tomcat 4.0.x releases (including Tomcat 4.0.5),
which allows to use a specially crafted URL to return the
unprocessed source of a JSP page, or, under special
circumstances, a static resource which would otherwise have been
protected by security constraint, without the need for being
properly authenticated. This is based on a variant of the
exploit that was disclosed on
09/24/2002.
See:
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.6/RELEASE-NOTES
Notes
Notes:
svn path=/head/; revision=67783
Diffstat (limited to 'www/Makefile')
0 files changed, 0 insertions, 0 deletions