Comment 22 for bug 1496277

Revision history for this message
Steve Baker (steve-stevebaker) wrote : Re: [Bug 1496277] Re: template-validate may read server local files

On 22/09/15 02:33, Jeremy Stanley wrote:
> The exploit scenario described, referencing a large file or stream to
> consume system memory, doesn't seem like it would be limited to local
> paths. What mitigation is in place to prevent large remote files/streams
> via allowed protocol schemes from having a similar effect?
>
This particular code path only allows the file:// protocol