aboutsummaryrefslogtreecommitdiff
path: root/t
diff options
context:
space:
mode:
authorSimon McVittie <smcv@debian.org>2016-05-04 08:52:40 +0100
committerSimon McVittie <smcv@debian.org>2016-05-05 23:43:50 +0100
commit54a9f8d07de3bf853a74c34ca98bcb3ec9bc8ac7 (patch)
tree238e380782fd1f15f4ef0ee408e6c934a80ae08e /t
parent32ef584dc5abb6ddb9f794f94ea0b2934967bba7 (diff)
downloadikiwiki-54a9f8d07de3bf853a74c34ca98bcb3ec9bc8ac7.tar
ikiwiki-54a9f8d07de3bf853a74c34ca98bcb3ec9bc8ac7.tar.gz
img: force common Web formats to be interpreted according to extension
A site administrator might unwisely set allowed_attachments to something like '*.jpg or *.png'; if they do, an attacker could attach, for example, a SVG file named attachment.jpg. This mitigates CVE-2016-3714.
Diffstat (limited to 't')
0 files changed, 0 insertions, 0 deletions