You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since last vulnerabilities with GhostScript, and because ImageMagick use it (for example when we use convert), should we include and modify the current examples to use ones that check for magic bytes ?
I agree that it should be a part of the project and we should at least provide an example how to properly validate the files. I'm looking into how to implement this.
to address the stavro/arc#263 from @speeddragon and stavro/arc#73 from @cichaczem
Since last vulnerabilities with GhostScript, and because ImageMagick use it (for example when we use
convert
), should we include and modify the current examples to use ones that check for magic bytes ?So instead of using this for image validation,
I can also try to add for GIF or other file formats.
The text was updated successfully, but these errors were encountered: