Re: Message delimiting security issues

Travis Snoozy schrieb:
> On Wed, Jan 17, 2007 at 11:47:33AM +0100, Henrik Nordstrom wrote:
> <snip>
>> Does the implied LWS rule apply to header names, even if it's not
>> allowed in MIME? Allowing LWS around the header name does not make
>> sense, but it is not explicitly forbidden.
> 
> LWS is not allowed.
> 
> <snip>
>> Content-Length : 100
> 
> BNF makes it clear.
> 
> token          = 1*<any CHAR except CTLs or separators>
> message-header = field-name ":" [ field-value ]
> field-name     = token
> separator      = [...] | SP | HT
> ...

Are you aware of the "implied LWS" rule? 
(<http://greenbytes.de/tech/webdav/rfc2616.html#rfc.section.2.1.p.11>).

Best regards, Julian

Received on Wednesday, 17 January 2007 16:50:50 UTC