FastMail.FM Security Vulnerabilities
grepular.com
grepular.com
I disclosed them responsibly and they were fixed before I published this blog post.
As a Fastmail.fm user, thanks for your work in improving the service by notifying the team of these vulnerabilities.There should be a strict whitelist of allowed content types, and anything not on that list should be download only. The trouble is, people tend to put "image/*" on that list, because they don't know what an SVG is or what it can do.
Regarding the script injection from image file names, there is a simple solution to this problem: separate the data types of strings and document structure. For example:
http://www.gnu.org/software/guile/manual/html_node/Types-and...
[edit] I have alerted security@horde.org
[edit] They've confirmed the bug and intend to fix it by making "image/svg+xml" attachments download only. This is the same fix that FastMail used. Of course, everyone will need to upgrade when this has been done.
Thank you for the detection tool!
Edit: redacted vendor.
It would probably be better if people submitted these bugs directly to the vendor rather than making them immediately public. If you don't know how to do this, or how to describe the bug, you can let me know and I will do it on your behalf. My contact details are in my HN profile