GraphicsMagick 1.1.3 pending & security alert
Bob Friesenhahn <[email protected]> Thu, 5 Aug 2004 14:30:47 -0500 (CDT)
| Newsgroups | gmane.comp.video.graphicsmagick.announce |
|---|---|
| Message-ID | <[email protected]> |
This weekend I plan to prepare the GraphicsMagick 1.1.3 release. This release will be significant due to the following: o LZW compression will be enabled by default. o PNG security fixes will be included. For those of you who are not aware, all versions of libpng prior to 1.2.6rc1 are inflicted with a vulnerability. It is possible for a PNG file to contain executable content, which is executed due to exploiting this vulnerability. Please see "http://www.us-cert.gov/cas/techalerts/TA04-217A.html" for a formal description of this vulnerability and the recommended solution. The libpng vulnerability is significant since libpng is used by hundreds of software programs under many operating systems, including Windows. These programs include mail readers, web browsers, and GraphicsMagick. If you are using GraphicsMagick and libpng in an environment where you do not have tight control over the origin of the input files then I strongly recommend that you update to 1.2.6rc1 right away, or update your existing libpng with one of the available patch sets. Please note that since GraphicsMagick inspects the header of files to determine the file type, validating uploaded files by checking file extension is not sufficient. For example a file with the extension .jpg may actually be a PNG file and will be processed as a PNG file. Bob ====================================== Bob Friesenhahn [email protected] http://www.simplesystems.org/users/bfriesen ------------------------------------------------------- This SF.Net email is sponsored by OSTG. Have you noticed the changes on Linux.com, ITManagersJournal and NewsForge in the past few weeks? Now, one more big change to announce. We are now OSTG- Open Source Technology Group. Come see the changes on the new OSTG site. www.ostg.com