View Issue Details

IDProjectCategoryView StatusLast Update
0000705fileGeneralpublic2025-12-29 18:23
Reporterbana Assigned To 
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
Summary0000705: Question: Parsing untrusted data
DescriptionDuring some code reviews in other applications I came across multiple uses of file and libmagic where untrusted and sometimes even suspected malicious files were parsed to determine the file type. This seems kinda dangerous to me but I have not found any clear warnings or recommendations that would indicate if there are any recommended options to do this more safely or if this should be avoided altogether.
Considering how many application depend on this code, I am wondering if some general advice could be added to the documentation / man page

Thank you
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-12-29 18:23 bana New Issue