[Home] [By Thread] [By Date] [Recent Entries]

  • From: Liam R E Quin <liam@w...>
  • To: Hermann Stamm-Wilbrandt <STAMMW@d...>
  • Date: Fri, 31 Dec 2010 18:44:44 -0500

On Fri, 2010-12-31 at 20:02 +0100, Hermann Stamm-Wilbrandt wrote:
> Roger,
> 
> the input document size is not that important, see here:
> http://en.wikipedia.org/wiki/Billion_laughs
> 
> That file is of size 3928 bytes and will kill everything -- if no XML
> threat protection is in place:
> http://stamm-wilbrandt.de/en/xsl-list/laughs.128.xml

But, this just shows that some Web browsers had a vulnerability.

I'm not sure why this continues to interest people, beyond the fact that
some browsers continue to have the vulnerability.

Liam

-- 
Liam Quin - XML Activity Lead, W3C, http://www.w3.org/People/Quin/
Pictures from old books: http://fromoldbooks.org/
Ankh: irc.sorcery.net irc.gnome.org www.advogato.org



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]


Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member