Hacker News new | past | comments | ask | show | jobs | submit login

Apparently Paperclip library already covered this long before this vulnerability is published.


Well, they check the filetype. I wouldn't be so certain that covers all the bases. Read this: http://www.openwall.com/lists/oss-security/2016/05/03/18

Of course I would like to see specific tests that covers everything about this vulnerability. I see now that there are more problems than the one mentioned in the article.

But the link submitted to hackernews specifically mentioned "magic bytes" which is the file type problem. I think Paperclip is not affected on that one.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
