oss-sec mailing list archives
GraphicsMagick Response To "ImageTragick"
From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Sun, 8 May 2016 19:48:49 -0500 (CDT)
The GraphicsMagick project response to the recent "ImageTragick" (https://imagetragick.com/) exploits may be found in an email posted to the GraphicsMagick announcements mail list and which may be found archived here: "https://sourceforge.net/p/graphicsmagick/mailman/message/35072963/".
The most important concern noted is that a shell exploit is possible via the "gplt" entry in the delegates.mgk file. While GraphicsMagick does escape individual Unix shell arguments appropriately, the gnuplot load request can be used to invoke gnuplot's system() command. The mere existence of a system() command makes gnuplot files entirely unsecure and it is a very dangerous format.
Unfortunately, I see that SourceForge converted the several patches into MS-DOS format.
Bob -- Bob Friesenhahn bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/ GraphicsMagick Maintainer, http://www.GraphicsMagick.org/
Current thread:
- GraphicsMagick Response To "ImageTragick" Bob Friesenhahn (May 08)
- <Possible follow-ups>
- GraphicsMagick Response To "ImageTragick" Bob Friesenhahn (May 09)
- Re: GraphicsMagick Response To "ImageTragick" Simon McVittie (May 09)
- Re: GraphicsMagick Response To "ImageTragick" Bob Friesenhahn (May 09)
- Re: GraphicsMagick Response To "ImageTragick" Simon McVittie (May 09)
- Re: GraphicsMagick Response To "ImageTragick" Bob Friesenhahn (May 09)
- Re: GraphicsMagick Response To "ImageTragick" Simon McVittie (May 09)
- Re: GraphicsMagick Response To "ImageTragick" John Lightsey (May 09)
- Re: GraphicsMagick Response To "ImageTragick" David Chan (May 12)