Frank:

Thanks for your effort to eliminate this security risk in OO Base.

Frank wrote:
> In fact, we plan to change the loading of the HSQLDB driver to use a
> dedicated class loader, which explicitly looks for the version in the
> OOo installation (and none else).

This a reliable and secure solution, and yet still flexible when
implemented in conjunction with user configurable list of extension
library directories which you discussed in another message.  A user
configurable list is useful for managing component software used by many
front end applications, like hsqldb.jar used by OO Base and numerous
other front ends.

Ray

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to