oss-sec mailing list archives
Re: ImageMagick Is On Fire -- CVE-2016-3714
From: Simon McVittie <smcv () debian org>
Date: Thu, 19 May 2016 20:00:37 +0100
On Thu, 19 May 2016 at 12:25:09 -0600, Kurt Seifried wrote:
Without making a commercial pitch for the company I work ... I suspect one aspect of other vendors not fixing this is that there is a very simple/effective/verifiable workaround to prevent exploitation of this
Having looked into it a bit for Debian, there are several factors: * mitigations exist, like you said * many of the upstream fixes in ImageMagick are not clearly separated from random other changes (I found one in a commit labelled "Update to the latest autoconf / automake"!) * many of the upstream fixes in ImageMagick (and GraphicsMagick) are really just mitigations too, and they remove features that someone could conceivably have been using, which rather goes against the idea of a stable release with a fixed feature-set (yes, I realise some of those features cannot be done securely) * there are a large number of other issues found via fuzzing, in coders for miscellaneous formats that you'll probably never see "in the wild", which could conceivably also be security vulnerabilities but probably aren't feasible to backport to old releases Bob, if you would like distributions to pick up GraphicsMagick security fixes in a timely way, it would probably be really useful to do an upstream release - distributions are typically a lot more confident about backporting large changes to their stable branches without regressions if they've been able to get some testing on the same changes in their unstable branches first. S
Current thread:
- Re: ImageMagick Is On Fire -- CVE-2016-3714, (continued)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Seth Arnold (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Tim (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Brandon Dees (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Seth Arnold (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Seth Arnold (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Jeremy Stanley (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Kurt Seifried (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Simon McVittie (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 John Lightsey (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 20)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Simon Lees (May 20)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Thomas Klausner (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Sven Kieske (May 20)