I'm sorry, but during the course of the attachment opening, even top takes about 10 seconds to start and the server is completely unusable. I can easily kill the machine with a recursive wget of the attachment. How would that not be considered a security issue?

Roman

On 17/11/05, Marc Groot Koerkamp <[EMAIL PROTECTED]> wrote:
On Mon, November 14, 2005 13:26, Roman Gaufman wrote:
> Hey,
>
>
> I have a major problem with squirrelmail. With the attached attachment,
> If I
> press download, everything is fine, but if I press view, the mailserver
> just hangs for 30 seconds: It takes top ~15 seconds to start and shows
> 100% cpu
> utilization by apache2, uptime shows a load average of 5 for the duration
> of opening the attachment and no one can use webmail or apache. The
> attachment opens eventually and there are no errors.

The timeout is caused by the html filter used in SquirrelMail. It's not
capable of filtering large html attachments.

Regards,

Marc Groot Koerkamp.



-------------------------------------------------------
This SF.Net email is sponsored by the JBoss Inc.  Get Certified Today
Register for a JBoss Training Course.  Free Certification Exam
for All Training Attendees Through End of 2005. For more info visit:
http://ads.osdn.com/?ad_id=7628&alloc_id=16845&op=click
--
squirrelmail-users mailing list
Posting Guidelines: http://www.squirrelmail.org/wiki/MailingListPostingGuidelines
List Address: squirrelmail-users@lists.sourceforge.net
List Archives: http://news.gmane.org/thread.php?group=gmane.mail.squirrelmail.user
List Archives:  http://sourceforge.net/mailarchive/forum.php?forum_id=2995
List Info: https://lists.sourceforge.net/lists/listinfo/squirrelmail-users

Reply via email to