fanquake
commented at 9:10 AM on June 23, 2019:
member
Major changes in expat 2.2.7:
#186#262 Fix extraction of namespace prefixes from XML names;
XML names with multiple colons could end up in the
wrong namespace, and take a high amount of RAM and CPU
resources while processing, opening the door to use for denial-of-service attacks
#227 Autotools: Add --without-examples and --without-tests
fanquake added the label Build system on Jun 23, 2019
fanquake added the label Needs gitian build on Jun 23, 2019
DrahtBot removed the label Needs gitian build on Jun 24, 2019
laanwj
commented at 5:48 PM on June 25, 2019:
member
and take a high amount of RAM and CPU
resources while processing, opening the door to use for denial-of-service attacks
This would only be a problem if anything llnking expat would be importing XML from untrusted sources, right?
It doesn't even end up in the final binary, it's only used indirectly for tooling (by Qt).
I don't think there's any need to worry about DoS attacks from this.
MarcoFalke deleted a comment on Jul 2, 2019
MarcoFalke added the label Needs gitian build on Jul 2, 2019
DrahtBot removed the label Needs gitian build on Jul 3, 2019
DrahtBot
commented at 9:52 AM on July 7, 2019:
member
<!--e57a25ab6845829454e8d69fc972939a-->
The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.
<!--174a7506f384e20aa4161008e828411d-->
Conflicts
No conflicts as of last run.
dongcarl
commented at 2:45 PM on July 8, 2019:
member
This is a metadata mirror of the GitHub repository
bitcoin/bitcoin.
This site is not affiliated with GitHub.
Content is generated from a GitHub metadata backup.
generated: 2026-04-15 15:14 UTC
This site is hosted by @0xB10C More mirrored repositories can be found on mirror.b10c.me