GraphicsMagick 1.1.3 pending & security alert

Bob Friesenhahn <[email protected]> Thu, 5 Aug 2004 14:30:47 -0500 (CDT)
Newsgroups gmane.comp.video.graphicsmagick.announce
Message-ID <[email protected]>
This weekend I plan to prepare the GraphicsMagick 1.1.3 release.  This 
release will be significant due to the following:

   o LZW compression will be enabled by default.
   o PNG security fixes will be included.

For those of you who are not aware, all versions of libpng prior to 
1.2.6rc1 are inflicted with a vulnerability.  It is possible for a PNG 
file to contain executable content, which is executed due to 
exploiting this vulnerability. Please see 
"http://www.us-cert.gov/cas/techalerts/TA04-217A.html" for a formal 
description of this vulnerability and the recommended solution.

The libpng vulnerability is significant since libpng is used by 
hundreds of software programs under many operating systems, including 
Windows. These programs include mail readers, web browsers, and 
GraphicsMagick.  If you are using GraphicsMagick and libpng in an 
environment where you do not have tight control over the origin of the 
input files then I strongly recommend that you update to 1.2.6rc1 
right away, or update your existing libpng with one of the available 
patch sets.

Please note that since GraphicsMagick inspects the header of files to 
determine the file type, validating uploaded files by checking file 
extension is not sufficient.  For example a file with the extension 
.jpg may actually be a PNG file and will be processed as a PNG file.

Bob
======================================
Bob Friesenhahn
[email protected]
http://www.simplesystems.org/users/bfriesen


-------------------------------------------------------
This SF.Net email is sponsored by OSTG. Have you noticed the changes on
Linux.com, ITManagersJournal and NewsForge in the past few weeks? Now,
one more big change to announce. We are now OSTG- Open Source Technology
Group. Come see the changes on the new OSTG site. www.ostg.com