Skip to content

Comment on XML flaws threaten 'enormous' array of apps

Comments

Pretty skeptical this flaw could be in "virtually every open-source XML library available". Seems unlikely a million brains collectively missed whatever this is.

You are underestimating how easy it is to write insecure C code.

But it would be nice to know if this is expat, libxml2, or what.

My understanding is it's not a single flaw. Virtually every XML library available is flawed, but each in their own way.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.