Comment 41 for bug 1415087

Revision history for this message
Mike Perez (thingee) wrote : Re: Format-guessing and file disclosure in image convert (CVE-2015-1850)

Apologies on the time it took to verify Eric's patch. I have verified this workaround works. It stops all uploads that have a backing file as mentioned in the commit message.