GraphicsMagick 1.1.12 Released

Bob Friesenhahn <[email protected]> Mon, 28 Apr 2008 13:18:41 -0500 (CDT)
Newsgroups gmane.comp.video.graphicsmagick.announce
Message-ID <[email protected]>
GraphicsMagick 1.1.12 is now released.  This release helps diminish 
the risk of external delegate exploits, and X11 exploits, via 
carefully-crafted file names.  For example, prior to this release, an 
X11 screen capture could be triggered, a web browser could be started, 
a job could be sent to the printer, and The GIMP could be started, due 
to requesting the read or write of ordinary-looking file names with 
particular extensions.  This issue is not new and in fact has existed 
in ImageMagick since the '90s.

Other than potential denial of service, we are not aware of a way to 
gain access to the system due to this weakness, but we are not very 
imaginative.  The simple solution is to upgrade server installations 
used to process user-provided files to this release.

Since GraphicsMagick 1.2 should be released within the next two weeks, 
there are no Windows install packages for GraphicsMagick 1.1.12.

GraphicsMagick 1.1.12 source code may be downloaded from SourceForge 
at "http://sourceforge.net/project/showfiles.php?group_id=73485".

The following is the NEWS for this update:

Significant changes associated with GraphicsMagick 1.1.12 (released April 28, 2008)

   Security Fixes:

     o Do not access X11 or invoke convenience or stealth delegate
       programs based on the file extension. In particular, these file
       extensions are rejected for consideration as a format specifier:
       'autotrace', 'browse', 'dcraw', 'edit', 'gs-color',
       'gs-color+alpha', 'gs-gray', 'gs-mono', 'launch', 'mpeg-encode',
       'print', 'scan', 'show', 'win', 'xc', and 'x'.

   Bugs Fixed:

     o magick/effect.c: Should now compile for ARM CPU.

     o TIFF: Don't request Kodak private tags since these cause some
       versions of libtiff to misbehave.

     o When performing string expansion of image attribute identifiers, skip
       those which require access to image pixels if image pixels are not
       present.

     o CropImageToHBITMAP(), ImageToHBITMAP(): Fix leak of bitmap handle.

Thanks,

Bob
======================================
Bob Friesenhahn
[email protected], http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/


-------------------------------------------------------------------------
This SF.net email is sponsored by the 2008 JavaOne(SM) Conference 
Don't miss this year's exciting event. There's still time to save $100. 
Use priority code J8TL2D2. 
http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone