r71548 MediaWiki - Code Review archive

Repository:MediaWiki
Revision:r71547‎ | r71548 | r71549 >
Date:09:51, 24 August 2010
Author:tstarling
Status:ok
Tags:
Comment:
A little extra paranoia. We wouldn't want a vulnerability in identify or tiffinfo or exiv2 or their output parsers to lead to arbitrary shell execution.
Modified paths:
  • /trunk/extensions/PagedTiffHandler/PagedTiffHandler.image.php (modified) (history)

Diff [purge]

Index: trunk/extensions/PagedTiffHandler/PagedTiffHandler.image.php
@@ -63,8 +63,8 @@
6464 public static function getPageSize( $data, $page ) {
6565 if ( isset( $data['page_data'][$page] ) ) {
6666 return array(
67 - 'width' => $data['page_data'][$page]['width'],
68 - 'height' => $data['page_data'][$page]['height']
 67+ 'width' => intval( $data['page_data'][$page]['width'] ),
 68+ 'height' => intval( $data['page_data'][$page]['height'] )
6969 );
7070 }
7171 return false;

Follow-up revisions

RevisionCommit summaryAuthorDate
r71623Updated to trunk head (r71204, r71548, i18n)tstarling06:24, 25 August 2010

Status & tagging log