(no title)
zetafunction | 3 months ago
Disclaimer: I work on Chrome and have occasionally dabbled in libxml2/libxslt in the past, but I'm not directly involved in any of the current work.
zetafunction | 3 months ago
Disclaimer: I work on Chrome and have occasionally dabbled in libxml2/libxslt in the past, but I'm not directly involved in any of the current work.
inejge|3 months ago
nwellnhof|3 months ago
Ygg2|3 months ago
mananaysiempre|3 months ago
Mikhail_Edoshin|3 months ago
Other vectors probably mean a single vector: external entities, where a) you process untrusted XML on server and b) allow the processor to read external entities. This is not a bug, but early versions of XML processors may lack an option to disallow access to external entities. This also has been fixed.
XSLT has no exploits at all, that is no features that can be misused.
fabrice_d|3 months ago