[issue18317] gettext: DoS via crafted Plural-Forms

Jakub Wilk report at bugs.python.org
Fri Jun 28 11:27:23 CEST 2013


Jakub Wilk added the comment:

Making token filtering more thorough may be simpler that going through AST.

I think Python should accept all the operators that GNU gettext accepts:
http://git.savannah.gnu.org/cgit/gettext.git/tree/gettext-runtime/intl/plural.y?id=v0.18.2.1#n132

----------

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue18317>
_______________________________________


More information about the Python-bugs-list mailing list