tomcat-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From bugzi...@apache.org
Subject DO NOT REPLY [Bug 37150] - denial of service on many and long requests on v5.5.x
Date Wed, 09 Nov 2005 22:18:34 GMT
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG·
RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT
<http://issues.apache.org/bugzilla/show_bug.cgi?id=37150>.
ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND·
INSERTED IN THE BUG DATABASE.

http://issues.apache.org/bugzilla/show_bug.cgi?id=37150


markt@apache.org changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|REOPENED                    |RESOLVED
         Resolution|                            |FIXED




------- Additional Comments From markt@apache.org  2005-11-09 23:18 -------
This is now fixed.

The obvious optimisation has been made in the code but this only has a marginal
impact.

Given the high cost of generating the listings in Java, this code cannot be
optimised to the point where large directory listings will not place a
disproportionate load on the server. Therefore, directory listing is now
disabled by default and warnings have been added to both the documentation and
the file where this is configured.

These changes will be included in versions 5.5.13+, 5.0.31+ and 4.1.32+

Note that releases of the 4.1.x and 5.0.x branches are now infrequent and that
none are planned at present.

-- 
Configure bugmail: http://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


Mime
View raw message