From fd0ca2f3a02c1b54be1bd16b9d22546428176ce6 Mon Sep 17 00:00:00 2001 From: Darian Anthony Patrick Date: Wed, 12 Aug 2015 12:47:36 -0700 Subject: [PATCH] Avoid exposure of local path in PNG thumbnails Bug: T108616 Change-Id: I952068d2d175d71f86dec0dbb92af5a122c05a49 --- includes/media/Bitmap.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/includes/media/Bitmap.php b/includes/media/Bitmap.php index 692e5a644f..faf40b3029 100644 --- a/includes/media/Bitmap.php +++ b/includes/media/Bitmap.php @@ -161,6 +161,8 @@ class BitmapHandler extends TransformationalImageHandler { ( $params['comment'] !== '' ? array( '-set', 'comment', $this->escapeMagickProperty( $params['comment'] ) ) : array() ), + // T108616: Avoid exposure of local file path + array( '+set', 'Thumb::URI' ), array( '-depth', 8 ), $sharpen, array( '-rotate', "-$rotation" ), -- 2.20.1