Re: Postscript is not scriptable? (2.7.4 Content-Type sniffing)

On Fri, 29 Aug 2008, Dan Connolly wrote:
> 
> I'm trying to understand the table in 2.7.4 Content-Type sniffing.
> 
> application/postscript has "Safe" in the "Security" column.
> 
> Is that a typo?

That just means that sniffing that type when the file is labeled as 
text/plain but is found to contain binary data of some kind isn't a 
privilege escalation risk.

Is that wrong?

-- 
Ian Hickson               U+1047E                )\._.,--....,'``.    fL
http://ln.hixie.ch/       U+263A                /,   _.. \   _\  ;`._ ,.
Things that are impossible just take longer.   `._.-(,_..'--(,_..'`-.;.'

Received on Friday, 29 August 2008 20:52:22 UTC