note 87188 added to function.getimagesize

From: Date: Sun, 23 Nov 2008 16:30:55 +0000
Subject: note 87188 added to function.getimagesize
Groups: php.notes 
Request: Send a blank email to php-notes+get-146845@lists.php.net to get a copy of this message
Note that if you specify a remote file (via a URL) to check the size of, PHP will first download the remote file to your server. If you're using this function to check the size of user provided image links, this could constitute a security risk. A malicious user could potentially link to a very large image file and cause PHP to download it. I do not know what, if any, file size limits are in place for the download. But suppose the user provided a link to an image that was several gigabytes in size? It would be nice if there were a way to limit the size of the download performed by this function. Hopefully there is already a default with some sensible limits. ---- Server IP: 209.41.74.194 Probable Submitter: 173.64.218.123 ---- Manual Page -- http://www.php.net/manual/en/function.getimagesize.php Edit -- https://master.php.net/note/edit/87188 Del: integrated -- https://master.php.net/note/delete/87188/integrated Del: useless -- https://master.php.net/note/delete/87188/useless Del: bad code -- https://master.php.net/note/delete/87188/bad+code Del: spam -- https://master.php.net/note/delete/87188/spam Del: non-english -- https://master.php.net/note/delete/87188/non-english Del: in docs -- https://master.php.net/note/delete/87188/in+docs Del: other reasons-- https://master.php.net/note/delete/87188 Reject -- https://master.php.net/note/reject/87188 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#146845) next »