[wp-trac] [WordPress Trac] #40175: Upload Validation / MIME Handling

WordPress Trac noreply at wordpress.org
Thu Mar 23 21:42:30 UTC 2017


#40175: Upload Validation / MIME Handling
--------------------------+------------------------------
 Reporter:  blobfolio     |       Owner:  joemcgill
     Type:  defect (bug)  |      Status:  accepted
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  Media         |     Version:  4.7.3
 Severity:  critical      |  Resolution:
 Keywords:                |     Focuses:
--------------------------+------------------------------

Comment (by blobfolio):

 The proposed fix (via #39963) has been repackaged as a plugin for broader
 testing! (The ticket also includes the changes as a patch if you'd rather
 apply it that way.)

 For anybody affected by the issues in this ticket, please give it a try:
 https://core.trac.wordpress.org/attachment/ticket/39963/blob-mimes.zip

 If you install it, please be sure to follow #39963 so you are kept abreast
 of plugin updates, if any. And of course, report any happy or sad news
 from your use there.

 For reference, it is pretty much the opposite of the earlier quick-fix
 https://wordpress.org/plugins/disable-real-mime-check/. It does '''not'''
 disable the security features introduced in `4.7.1` — in fact it greatly
 expands them — but instead is much smarter about reconciling the variation
 in type detection that exists from server to server.

 @lovelucy, this also addresses the detection inconsistencies we've seen
 within a single file "type". Please let me know if it fixes your Excel
 document upload issues.

 Thanks everyone!

--
Ticket URL: <https://core.trac.wordpress.org/ticket/40175#comment:11>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list