[Home] [By Thread] [By Date] [Recent Entries]


Bullard, Claude L (Len) wrote:
> "XML mechanisms that follow external references (External References) may also
 > expose an implementation to various threats by causing the 
implementation to
 > access external resources automatically.

> Hmm.  So namespacesCumURLs are a security problem?

No, a namespace URI is an identifier, and therefore need not be 
followed. The document (which is excellent) is talking about, you know, 
external ENTITY things.

I believe this security issue is one reason why SOAP disallows DTD's.
	/r$



Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member