Re: [Python-Dev] XML DoS vulnerabilities and exploits in Python

2013年2月20日 23:48:15 -0800

On 2013年2月21日 02:29:08 -0500
Tres Seaver <[email protected]> wrote:
> 
> Antoine,
> 
> A single, small,, malicious XML file can kill a machine (not just the
> process parsing it) by sucking all available RAM. We are talking hard
> lockup, reboot-to-fix-it sorts of DOC here.
Sure, but in many instances, rebooting a machine is not
business-threatening. You will have a couple of minutes' downtime and
that's all. Which is why the attack must be repeated many times to be a
major annoyance.
Regards
Antoine.
_______________________________________________
Python-Dev mailing list
[email protected]
http://mail.python.org/mailman/listinfo/python-dev
Unsubscribe: 
http://mail.python.org/mailman/options/python-dev/archive%40mail-archive.com

Reply via email to