Comment 52 for bug 1100282

Revision history for this message
Thierry Carrez (ttx) wrote : Re: DoS through XML entity expansion

@Dan: Thx for the updated patches. Agree that Oslo can be fixed after disclosure.

@Christian: Thx for reaching out, still busy traveling back from FOSDEM and will be fully up to speed again starting Wednesday. I'm handling the disclosure process for this bug and I was wondering if we (OpenStack) can proceed in responsible disclosure or if you wanted to coordinate the python stdlib security fix(es) with ours. I see some urgency in the fact that this issue was independently reported to us 4 times over the last two weeks, which means there is research/pentest activity around this. How far are you from public disclosure on your side ?