top | item 40859560

(no title)

nieve | 1 year ago

It allows full RCE from an uploaded or opened file. That seems reasonably critical to me.

discuss

order

worthless-trash|1 year ago

Thats.. in bad faith.

If thats the qualification for "remote" then you can say that every attack is remote and it clearly isnt.

out_of_protocol|1 year ago

Does this work with .pdf files? i.e. attacker uploads evil.pdf

llimllib|1 year ago

yes, also with .eps files