A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://www.mail-archive.com/html5lib-discuss@googlegroups.com/msg00235.html below:

DOS vulnerability when using HTML5 Sanitization

Comment #2 on issue 83 by excors: DOS vulnerability when using HTML5  
Sanitization
http://code.google.com/p/html5lib/issues/detail?id=83
This problem affects the Python implementation too.

In the Python version, it looks like the problem is the line

   if not re.match("^(\s*[-\w]+\s*:\s*[^:;]*(;|$))*$", style): return ''

which can seemingly take exponential time to run. (As an example, see

   re.match("^(\s*[-\w]+\s*:\s*[^:;]*(;|$))*$", 'x: y; ' * 21)

which is really slow. The space at the end of the expression makes it not  
match the
pattern, and so it does a load of backtracking and takes forever.)

-- 
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
http://code.google.com/hosting/settings

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"html5lib-discuss" group.
 To post to this group, send email to html5lib-discuss@googlegroups.com
 To unsubscribe from this group, send email to [EMAIL PROTECTED]
 For more options, visit this group at 
http://groups.google.com/group/html5lib-discuss?hl=en-GB
-~----------~----~----~----~------~----~------~--~---


RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4