Comment 21 for bug 1496277

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: template-validate may read server local files

The exploit scenario described, referencing a large file or stream to consume system memory, doesn't seem like it would be limited to local paths. What mitigation is in place to prevent large remote files/streams via allowed protocol schemes from having a similar effect?