The results of an attack on a vulnerable XML library can be fairly dramatic.
With just a few hundred Bytes of XML data an attacker can occupy several
Gigabytes of memory within seconds. An attacker can also keep CPUs busy for a
long time with a small to medium size request. Under some circumstances it is
even possible to access local files on your server, to circumvent a firewall,
or to abuse services to rebound attacks to third parties. This library allows
for XML to be parsed in a manner that avoids these pitfalls.
Maintained by: Markus Rinne
Keywords: xml,bomb,protection,stdlib
ChangeLog: defusedxml
Homepage:
https://pypi.python.org/pypi/defusedxml
Download SlackBuild:
defusedxml.tar.gz
defusedxml.tar.gz.asc (FAQ)
(the SlackBuild does not include the source)
Individual Files: |
README |
defusedxml.SlackBuild |
defusedxml.info |
slack-desc |
© 2006-2024 SlackBuilds.org Project. All rights reserved.
Slackware® is a registered trademark of
Patrick Volkerding
Linux® is a registered trademark of
Linus Torvalds