[issue42051] plistlib inherits XML vulnerabilities: we should document them

Ronald Oussoren report at bugs.python.org
Mon Oct 19 05:26:00 EDT 2020


Ronald Oussoren <ronaldoussoren at mac.com> added the comment:

The PR is fairly simple: Just reject files with entity declarations as invalid files. Adding an option to accept entity declarations should not be necessary as Apple tools won't accept these declarations.

----------

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue42051>
_______________________________________


More information about the Python-bugs-list mailing list