Details
-
Bug
-
Resolution: Done
-
P1: Critical
-
5.5.0
-
None
-
Linux, Windows
-
fd4be84d23a0db4186cb42e736a9de3af722c7f7 (qt/qtbase/dev) f432c08882ffebe5074ea28de871559a98a4d094 (qt/qtbase/5.12.8)
Description
a svg can be made to contain a xml bomb (https://en.wikipedia.org/wiki/Billion_laughs).
When Qt tries to parse the svg an out of memory situation may occur. I.e. no detection of reference loops exist.
Attachments
Issue Links
- is duplicated by
-
QTBUG-50748 XMLStreamReader vulnerable to XML 'bomb'
- Closed
- relates to
-
QTBUG-82153 Exponential use node instantiation in SVG
- Closed