Last modified: 2011-01-25 00:36:54 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T24933, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 22933 - Upload a new version bypasses file extension checks
Upload a new version bypasses file extension checks
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
File management (Other open bugs)
unspecified
All All
: Normal major (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2010-03-23 20:21 UTC by Derk-Jan Hartman
Modified: 2011-01-25 00:36 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Derk-Jan Hartman 2010-03-23 20:21:35 UTC
When you choose "upload a new version", you can upload an arbitrary file type. For instance, you can upload a gif and then reupload a BMP file on top of it.

By default this will succeed, because by default the "ignore warnings" option is checked. This cannot be the intent. The ignore warnings option should probably not be checked by default.
Comment 1 Derk-Jan Hartman 2010-03-23 20:37:31 UTC
The upload form itself only gives the warning "There's already a file with that name. Do you want to overwrite it?", and it does not say anything about the changed filetype either.
Comment 2 Derk-Jan Hartman 2010-04-01 13:19:37 UTC
This issue is fixed in trunk, but still broken in wmf-deployment.
Comment 3 Bryan Tong Minh 2010-04-11 21:18:25 UTC
Probably fixed with the recent deployment?

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links