diff options
author | Simon McVittie <smcv@debian.org> | 2016-05-04 08:52:40 +0100 |
---|---|---|
committer | Simon McVittie <smcv@debian.org> | 2016-05-05 23:43:50 +0100 |
commit | 54a9f8d07de3bf853a74c34ca98bcb3ec9bc8ac7 (patch) | |
tree | 238e380782fd1f15f4ef0ee408e6c934a80ae08e /t/img | |
parent | 32ef584dc5abb6ddb9f794f94ea0b2934967bba7 (diff) | |
download | ikiwiki-54a9f8d07de3bf853a74c34ca98bcb3ec9bc8ac7.tar ikiwiki-54a9f8d07de3bf853a74c34ca98bcb3ec9bc8ac7.tar.gz |
img: force common Web formats to be interpreted according to extension
A site administrator might unwisely set allowed_attachments to
something like '*.jpg or *.png'; if they do, an attacker could attach,
for example, a SVG file named attachment.jpg.
This mitigates CVE-2016-3714.
Diffstat (limited to 't/img')
0 files changed, 0 insertions, 0 deletions