OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.


Help: OASIS Mailing Lists Help | MarkMail Help

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]
Re: [xml-dev] Results of trying to load a 137MB XML document intoIE, Firefox, and Opera

On Fri, 2010-12-31 at 20:02 +0100, Hermann Stamm-Wilbrandt wrote:
> Roger,
> the input document size is not that important, see here:
> http://en.wikipedia.org/wiki/Billion_laughs
> That file is of size 3928 bytes and will kill everything -- if no XML
> threat protection is in place:
> http://stamm-wilbrandt.de/en/xsl-list/laughs.128.xml

But, this just shows that some Web browsers had a vulnerability.

I'm not sure why this continues to interest people, beyond the fact that
some browsers continue to have the vulnerability.


Liam Quin - XML Activity Lead, W3C, http://www.w3.org/People/Quin/
Pictures from old books: http://fromoldbooks.org/
Ankh: irc.sorcery.net irc.gnome.org www.advogato.org

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]

News | XML in Industry | Calendar | XML Registry
Marketplace | Resources | MyXML.org | Sponsors | Privacy Statement

Copyright 1993-2007 XML.org. This site is hosted by OASIS