Bug 312912

Summary: Kolourpaint susceptible to a billion laughs
Product: [Applications] kolourpaint Reporter: stud4 <johh3125>
Component: generalAssignee: kolourpaint-support
Status: RESOLVED UPSTREAM    
Severity: normal CC: cfeck
Priority: NOR    
Version: unspecified   
Target Milestone: ---   
Platform: Debian testing   
OS: Other   
URL: http://pastebin.com/XqcV3eHM
Latest Commit: Version Fixed In:
Attachments: Prepared svg file

Description stud4 2013-01-08 22:01:31 UTC
Kolourpaint allocates several gigabytes of memory and then crashes when opening a preperated SVG (see link) with a billion laughs (http://en.wikipedia.org/wiki/Billion_laughs)



Reproducible: Always

Steps to Reproduce:
1. open the svg file
Actual Results:  
Program crashes when starting up

Expected Results:  
An error message about a broken file

kcrash file: http://pastebin.com/Ljx4PRjf
Comment 1 stud4 2013-01-08 22:03:08 UTC
Created attachment 76322 [details]
Prepared svg file
Comment 2 Christoph Feck 2013-01-08 23:38:01 UTC
Also happens when using a pure Qt based viewer. Please report this issue to Qt developers via http://qt-project.org/