[wp-trac] [WordPress Trac] #12284: I/O Sanity Failures With Invalid HTML Entity References

WordPress Trac wp-trac at lists.automattic.com
Thu Feb 25 13:37:43 UTC 2010


#12284: I/O Sanity Failures With Invalid HTML Entity References
-----------------------------+----------------------------------------------
 Reporter:  miqrogroove      |       Owner:  ryan     
     Type:  defect (bug)     |      Status:  new      
 Priority:  highest omg bbq  |   Milestone:  3.0      
Component:  Security         |     Version:           
 Severity:  blocker          |    Keywords:  has-patch
-----------------------------+----------------------------------------------

Comment(by miqrogroove):

 Added a patch to correct numeric entity logic in kses.  Tested min and max
 values for decimal and hex notation, with and without leading zeroes.
 Leading zeroes are preserved.  Pass/fail for numeric entities matches
 behavior of validator.w3.org, thanks mostly to function valid_unicode()
 already in kses.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/12284#comment:14>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list