View Single Post
Old 11-18-2017, 10:01 PM   #271
KevinH
Sigil Developer
KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.KevinH ought to be getting tired of karma fortunes by now.
 
Posts: 8,911
Karma: 6120478
Join Date: Nov 2009
Device: many
Yes recursive named entity expansion has been used to attack html sites. Since epubs use html5 for epub3 and since the same problems exist with webkits used in ebook viewers, it was probably a good idea. That said, I have no idea if there are malicious epubs in the wild but given there are malicious Word docs and PDFs in the wild, it is just a matter of time.

Last edited by KevinH; 11-19-2017 at 07:40 AM.
KevinH is offline   Reply With Quote