Page MenuHomePhabricator

running a dot program in an infinite loop
Closed, ResolvedPublic

Description

I haven't been able to verify this issue but I feel it's valid.

There are several specimens of graphviz dot files which sends the dot program into an infinite loop. Currently the dot ExecFuture doesn't have a timeout. I think it should have a timeout to prevent dot from over-loading the server with malicious graphviz code.

Event Timeline

skyronic raised the priority of this task from to Needs Triage.
skyronic updated the task description. (Show Details)
skyronic added a project: Remarkup.
skyronic added a subscriber: skyronic.

Yeah, I think this is reasonable.