Re: JPEG Upload

From: Date: Sat, 05 May 2012 22:16:23 +0000
Subject: Re: JPEG Upload
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-60481@lists.php.net to get a copy of this message
> Moreover, that still doesn't protect you, as it would be possible to > make a valid image where the payload happened in the image data... Agreed. But sanitizing input by silently removing blocks of data your users rightfully expect to be preserved? That's egregious, even if it "worked." (Like many such discussions, I almost can't believe we're having this one... I mean, executing images is just not normal whether or not you can "bear the (performance) cost." Who is doing this on purpose?) -- S.

« previous php.internals (#60481) next »