oss-sec mailing list archives

Re: ImageMagick identify "d:" hangs


From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Wed, 28 Sep 2016 17:15:53 -0500 (CDT)

On Wed, 28 Sep 2016, Tavis Ormandy wrote:

(/etc/passwd) /dumpname load 256 string filenameforall
$ convert test.gif png:test.png
<creates a file called test.png containing first line of /etc/passwd>

Also seems to work with gm convert.

It is good that you did not single out just one using program.

This issue seems to afflict any program which invokes Ghostscript in general and not just *Magick. However, 'convert' does offer to write a rendered result to an output file.

Bob
--
Bob Friesenhahn
bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/


Current thread: