fre 2009-06-26 klockan 12:05 -0600 skrev Alex Rousskov:

> TODO: simply truncating read content would not work for pipelined
> responses. We should preserve extra content for the next transaction on
> a pconn.

Correct, and is a major reason NOT to do pipelining as it then becomes
impossible to protect from the response splitting attack you just
closed...

Regards
Henrik

Reply via email to