Bug #83029

GIFBUILDER files cannot be delivered via web server

Added by Oliver Hader over 3 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
Image Generation / GIFBUILDER
Target version:
-
Start date:
2017-11-17
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
8
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

GIFBUILDER uses provided file names and text snippets in order to generate the final name for files to be written to. In case text snippets start with a dot, this is also reflected into the file name - preventing some web servers to deliver the file since it's considered to be internal.

Since directory separators are correctly converted there are no security vulnerabilities.

TypoScript:

page.20 = IMAGE
page.20.file = GIFBUILDER
page.20.file {
    XY = [10.w]+10, [10.h]+10
    backColor = #cc0000
    10 = TEXT
    10.text = .hello
    10.fontColor = #000000
    10.fontSize = 20
    10.offset = 0,20
}

#1

Updated by Gerrit Code Review over 3 years ago

  • Status changed from New to Under Review

Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/54677

#2

Updated by Oliver Hader over 3 years ago

  • Description updated (diff)
#3

Updated by Gerrit Code Review over 3 years ago

Patch set 1 for branch TYPO3_8-7 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/54712

#4

Updated by Oliver Hader over 3 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100
#5

Updated by Benni Mack over 2 years ago

  • Status changed from Resolved to Closed

Also available in: Atom PDF