Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

apply_corrections.py is very vulnerable to regex denial of service #359

Open
jesopo opened this issue Sep 9, 2019 · 0 comments
Open

apply_corrections.py is very vulnerable to regex denial of service #359

jesopo opened this issue Sep 9, 2019 · 0 comments
Labels
bug Unexpected problem or unintended behavior

Comments

@jesopo
Copy link
Contributor

jesopo commented Sep 9, 2019

A user sharing a channel with you can do the following:

<jesopo> aaaaaaaaaaaaaaaa
<jesopo> s/(.*\w){16}//

and hang your weechat at 100% CPU

@weechatter weechatter added the bug Unexpected problem or unintended behavior label Sep 9, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Unexpected problem or unintended behavior
Projects
None yet
Development

No branches or pull requests

2 participants