Return-Path: Delivered-To: apmail-jakarta-tomcat-dev-archive@apache.org Received: (qmail 18746 invoked from network); 22 Mar 2002 15:00:59 -0000 Received: from unknown (HELO nagoya.betaversion.org) (192.18.49.131) by daedalus.apache.org with SMTP; 22 Mar 2002 15:00:59 -0000 Received: (qmail 1462 invoked by uid 97); 22 Mar 2002 15:00:56 -0000 Delivered-To: qmlist-jakarta-archive-tomcat-dev@jakarta.apache.org Received: (qmail 1445 invoked by uid 97); 22 Mar 2002 15:00:55 -0000 Mailing-List: contact tomcat-dev-help@jakarta.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Subscribe: List-Help: List-Post: List-Id: "Tomcat Developers List" Reply-To: "Tomcat Developers List" Delivered-To: mailing list tomcat-dev@jakarta.apache.org Received: (qmail 1431 invoked by uid 50); 22 Mar 2002 15:00:55 -0000 Date: 22 Mar 2002 15:00:55 -0000 Message-ID: <20020322150055.1430.qmail@nagoya.betaversion.org> From: bugzilla@apache.org To: tomcat-dev@jakarta.apache.org Cc: Subject: DO NOT REPLY [Bug 7364] New: - compiler creates empty .java files for invalid URLs X-Spam-Rating: daedalus.apache.org 1.6.2 0/1000/N DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE. http://nagoya.apache.org/bugzilla/show_bug.cgi?id=7364 compiler creates empty .java files for invalid URLs Summary: compiler creates empty .java files for invalid URLs Product: Tomcat 4 Version: 4.0.2 Final Platform: Sun OS/Version: Solaris Status: NEW Severity: Minor Priority: Other Component: Jasper AssignedTo: tomcat-dev@jakarta.apache.org ReportedBy: fred@stsci.edu If you enter an invalid URL that ends with .jsp, Tomcat creates zero length files in the work directory that never get cleaned up. We see these a lot in development, but not too many with operational systems. Someone could use this to be mallicious and get the server into a state where you could not create new work files for valid URLs, so it should probably be fixed as a potential denial of service. Ie if the URL is invalid and the JSP file does not exist don't create the .java file in the work directory. Currently I have 11 of those zero length files due to type-o's on my part when entering the URL in the browser. -- To unsubscribe, e-mail: For additional commands, e-mail: