[SECURITY] RCE vulnerability in Horde_Image
Jan Schneider <[email protected]> Thu, 21 Sep 2017 14:08:41 +0000
| Newsgroups | gmane.comp.horde.announce,gmane.comp.horde.user |
|---|---|
| Message-ID | <[email protected]> |
Hello, a Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" utility. It's not exploitable through any Horde application, because the code path to the vulnerability is not used by any Horde code. Custom applications using the Horde_Image library might be affected though. This vulnerability affects all versions of Horde_Image from 2.0.0 to 2.5.1. A fixed version of the Horde_Image (version 2.5.2) library has already been released and everybody is advised to upgrade to Horde_Image 2.5.2 as soon as possible. Thanks to long-time contributor and supporter Thomas Jarosch <[email protected]> for discovering and reporting these vulnerabilities. -- Jan Schneider The Horde Project https://www.horde.org/ -- Horde announcements mailing list You are subscribed to this list as: [email protected] To unsubscribe, mail: [email protected]