You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@geronimo.apache.org by "Forrest Xia (Created) (JIRA)" <ji...@apache.org> on 2012/01/05 04:48:39 UTC

[jira] [Created] (GERONIMO-6253) Tomcat security patch of CVE-2011-4084 for G 2.2.1 release

Tomcat security patch of CVE-2011-4084 for G 2.2.1 release
----------------------------------------------------------

                 Key: GERONIMO-6253
                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
             Project: Geronimo
          Issue Type: Bug
      Security Level: public (Regular issues)
          Components: Tomcat
    Affects Versions: 2.2.1, 2.2
            Reporter: Forrest Xia


We need a fix for Geronimo 2.2.x release for the tomcat security patch of CVE-2011-4084.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Attachment: GEORNIMO-6253_binarypatch.zip

Attached a binary patch.

Steps to apply this patch into 2.2.1 release:
1. Stop the server
2. Remove folder "repository/org/apache/geronimo/ext/tomcat"
3. Detach the binary patch and unzip it into Geronimo folder, choose to override target files.
4. Start the server as usual and the patch is applied OK.

Please report any issue related to this patch if found.

                
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>         Attachments: GEORNIMO-6253_binarypatch.zip, GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Attachment: GERONIMO-6253.patch
                GEORNIMO-6253_binarypatch.zip

An updated patch to fix the issue of maxParameterCount value cannot be saved when server is restarted. See GERONIMO-6339 for details.
                
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>             Fix For: 2.2.1
>
>         Attachments: GEORNIMO-6253_binarypatch.zip, GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Assigned] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia reassigned GERONIMO-6253:
-------------------------------------

    Assignee: Forrest Xia
    
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>         Attachments: GEORNIMO-6253_binarypatch.zip, GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Attachment:     (was: GERONIMO-6253.patch)
    
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>             Fix For: 2.2.1
>
>         Attachments: GEORNIMO-6253_binarypatch.zip, GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Attachment: GERONIMO-6253.patch
                GEORNIMO-6253_binarypatch.zip
    
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>             Fix For: 2.2.1
>
>         Attachments: GEORNIMO-6253_binarypatch.zip, GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Attachment:     (was: GEORNIMO-6253_binarypatch.zip)
    
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>             Fix For: 2.2.1
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (Updated) (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Description: We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.  (was: We need a fix for Geronimo 2.2.x release for the tomcat security patch of CVE-2011-4084.)
        Summary: Improve parameter handling patch from tomcat community for G 2.2.1 release  (was: Tomcat security patch of CVE-2011-4084 for G 2.2.1 release)
    
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Commented] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
    [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13261303#comment-13261303 ] 

Forrest Xia commented on GERONIMO-6253:
---------------------------------------

Missing one module replacement in the binary patch, so reupload a new binary patch.
                
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>             Fix For: 2.2.1
>
>         Attachments: GEORNIMO-6253_binarypatch.zip, GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Resolved] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia resolved GERONIMO-6253.
-----------------------------------

       Resolution: Fixed
    Fix Version/s: 2.2.1
    
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>             Fix For: 2.2.1
>
>         Attachments: GEORNIMO-6253_binarypatch.zip, GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Attachment: GERONIMO-6253.patch

Code patch for 2.2.1 release, will try to attach a binary fix then.
                
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>         Attachments: GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Attachment:     (was: GERONIMO-6253.patch)
    
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>             Fix For: 2.2.1
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

[jira] [Updated] (GERONIMO-6253) Improve parameter handling patch from tomcat community for G 2.2.1 release

Posted by "Forrest Xia (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/GERONIMO-6253?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Forrest Xia updated GERONIMO-6253:
----------------------------------

    Attachment:     (was: GEORNIMO-6253_binarypatch.zip)
    
> Improve parameter handling patch from tomcat community for G 2.2.1 release
> --------------------------------------------------------------------------
>
>                 Key: GERONIMO-6253
>                 URL: https://issues.apache.org/jira/browse/GERONIMO-6253
>             Project: Geronimo
>          Issue Type: Bug
>      Security Level: public(Regular issues) 
>          Components: Tomcat
>    Affects Versions: 2.2, 2.2.1
>            Reporter: Forrest Xia
>            Assignee: Forrest Xia
>             Fix For: 2.2.1
>
>         Attachments: GEORNIMO-6253_binarypatch.zip, GERONIMO-6253.patch
>
>
> We need a fix for Geronimo 2.2.1 release for the parameter handling issue from Tomcat community.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira