httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Gregor J. Rothfuss" <>
Subject Re: Distributing httpd-2.2, redux
Date Fri, 30 Sep 2005 21:48:31 GMT
William A. Rowe, Jr. wrote:

> But given how lightweight zlib is, and how much of a moving target it
> was before 1.2.3, I'd strongly argue that 'deflate' is a core feature,
> that if we teach httpd to 'reinflate' there are many old vulnerabilites
> that we expose our users to, and that shipping 1.2.3 would add very
> little pain for much mod_deflate gain.

it might be worth turning mod_deflate on by default. there are still too 
many sites out there that do not have it on.

View raw message