In which languages is it a security hole to use user-supplied regular expression?

后端 未结 8 1542
爱一瞬间的悲伤
爱一瞬间的悲伤 2020-12-17 17:00

Edit: tchrist has informed me that my original accusations about Perl\'s insecurity are unfounded. However, the question still stands.

I know that i

8条回答
  •  盖世英雄少女心
    2020-12-17 17:29

    AFAIK, you can do it safely in C#: you can supply the regex string to the Regex constructor, and if it fails to parse it'll throw. I'm not sure about others.

提交回复
热议问题