Uploaded image for project: 'Qt'
  1. Qt
  2. QTBUG-135355

Doc: Improve security documentation of URI/URL/resource

    XMLWordPrintable

Details

    Description

      There are security issues with handling URIs and URLs from remote sources (network) and local sources (images, media, and so on).

      Go over what we currently cover and see how we can improve the security aspect of those Qt features. Specifically, URL and URI schemes and file loading and saving.

      References:

      1)There are several CWE entries for input handling, one of them is: 

      https://cwe.mitre.org/data/definitions/939.html

      2)RFC 8252 has a security consideration section that mentions URI schemes:

      https://datatracker.ietf.org/doc/html/rfc8252#section-8

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            jerome.pasion Jerome Pasion
            jerome.pasion Jerome Pasion
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:

              Gerrit Reviews

                There are no open Gerrit changes