3 ms·
Perl has taken care to address some of these issues. See 'Algorithmic Complexity Attacks' in perldoc perlsec. For example, the keys of a hash table are guaran
by bigmac 16y ago
Perl has taken care to address some of these issues. See 'Algorithmic Complexity Attacks' in perldoc perlsec. For example, the keys of a hash table are guaranteed to be returned in random order, to prevent hash collision attacks on the hashing algorithm itself.
It appears they punt on the particular issue of regex's running out of memory though. Developers are told "careful crafting of the regular expressions can help," and told to read "Mastering Regular Expressions."
As I recall, Boost's regex library will throw an exception if evaluation of the regex is getting out of hand.
It's funny, I generally judge a regex library on how compatible it is with perl's implementation. In this case though, I might actually prefer the behavior of Boost and PCRE.