funsec mailing list archives

Re: Format of embedded graphics


From: Florian Weimer <fw () deneb enyo de>
Date: Thu, 29 Dec 2005 22:03:54 +0100

* Larry Seltzer:

So what happens to the format of such a graphic when embedded in an HTML
e-mail? Is it forced to GIF or JPG, or is it perhaps still a WMF and
potentially malicious?

Imagemagick recognizes it as WMF, and tries to render it -- but I lack
the necessary wmf2eps tool, so this step fails.  (Gnus tries to
display it as a GIF image and fails, silently.)

Oh, and your test case prompted me to discover a shell-command
injection vulnerability in Imagemagick. *sigh*
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: