oss-sec mailing list archives

GraphicsMagick Response To "ImageTragick"


From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Sun, 8 May 2016 19:48:49 -0500 (CDT)

The GraphicsMagick project response to the recent "ImageTragick" (https://imagetragick.com/) exploits may be found in an email posted to the GraphicsMagick announcements mail list and which may be found archived here: "https://sourceforge.net/p/graphicsmagick/mailman/message/35072963/";.

The most important concern noted is that a shell exploit is possible via the "gplt" entry in the delegates.mgk file. While GraphicsMagick does escape individual Unix shell arguments appropriately, the gnuplot load request can be used to invoke gnuplot's system() command. The mere existence of a system() command makes gnuplot files entirely unsecure and it is a very dangerous format.

Unfortunately, I see that SourceForge converted the several patches into MS-DOS format.

Bob
--
Bob Friesenhahn
bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/


Current thread: