Images with unknown content: Dangerous for a browser?

Posted by chris_l on Stack Overflow See other posts from Stack Overflow or by chris_l
Published on 2010-06-11T11:57:20Z Indexed on 2010/06/11 12:12 UTC
Read the original article Hit count: 184

Filed under:
|
|
|
|

Let's say I allow users to link to any images they like. The link would be checked for syntactical correctness, escaping etc., and then inserted in an <img src="..."/> tag.

Are there any known security vulnerabilities, e.g. by someone linking to "evil.example.com/evil.jpg", and evil.jpg contains some code that will be executed due to a browser bug or something like that?

(Let's ignore CSRF attacks - it must suffice that I will only allow URLs with typical image file suffixes.)

© Stack Overflow or respective owner

Related posts about security

Related posts about browser