Re: I-D ACTION:draft-ietf-webdav-rfc2518bis-03.txt

> known issue.

Good, but that sentence you quoted contradicts it.  XML doesn't
allow subsetting.

> RFC2518bis specifically allows rejection  of requests using external
> entities (this should take care of the "one million laughs" attach).

Recursive entity declarations are internal entities.  :(

....Roy

Received on Thursday, 13 March 2003 15:49:57 UTC