RE: remote DoS in Mozilla 1.0

From: Jon Keating (jkeatingat_private)
Date: Tue Jun 11 2002 - 09:44:29 PDT

  • Next message: Tom: "Re: remote DoS in Mozilla 1.0"

    > Fixing XFS is indeed a good idea, but I submit that it is also a very
    > good idea to put a cap on font sizes in mozilla, and indeed anything 
    > else that accepts font rendering information from external sources.
    Writing stable software is a difficult process to do when you depend on
    other libraries to do their job the way you think it should be done.  The
    problem is a little more subtle than what is being discussed.  I am hearing
    that Mozilla should be updated, but the question is, what should the limit
    be for a font size?  The line has to be drawn somewhere and if each software
    puts it's own limit on the size of a font then larger fonts might not appear
    the same with different programs.  So, then XFS needs to be the definite
    place that draws the line.  I think this is a trivial problem because there
    are larger issues out there that are in essence the exact same thing that we
    discuss in this thread.
    Unfortunately, there is no easy answer because we put our dependence on a
    3rd party library.  This thread leaves a funny taste in my mouth.

    This archive was generated by hypermail 2b30 : Tue Jun 11 2002 - 10:07:21 PDT