GraphicsMagick 1.1.12 Released
Bob Friesenhahn <[email protected]> Mon, 28 Apr 2008 13:18:41 -0500 (CDT)
| Newsgroups | gmane.comp.video.graphicsmagick.announce |
|---|---|
| Message-ID | <[email protected]> |
GraphicsMagick 1.1.12 is now released. This release helps diminish
the risk of external delegate exploits, and X11 exploits, via
carefully-crafted file names. For example, prior to this release, an
X11 screen capture could be triggered, a web browser could be started,
a job could be sent to the printer, and The GIMP could be started, due
to requesting the read or write of ordinary-looking file names with
particular extensions. This issue is not new and in fact has existed
in ImageMagick since the '90s.
Other than potential denial of service, we are not aware of a way to
gain access to the system due to this weakness, but we are not very
imaginative. The simple solution is to upgrade server installations
used to process user-provided files to this release.
Since GraphicsMagick 1.2 should be released within the next two weeks,
there are no Windows install packages for GraphicsMagick 1.1.12.
GraphicsMagick 1.1.12 source code may be downloaded from SourceForge
at "http://sourceforge.net/project/showfiles.php?group_id=73485".
The following is the NEWS for this update:
Significant changes associated with GraphicsMagick 1.1.12 (released April 28, 2008)
Security Fixes:
o Do not access X11 or invoke convenience or stealth delegate
programs based on the file extension. In particular, these file
extensions are rejected for consideration as a format specifier:
'autotrace', 'browse', 'dcraw', 'edit', 'gs-color',
'gs-color+alpha', 'gs-gray', 'gs-mono', 'launch', 'mpeg-encode',
'print', 'scan', 'show', 'win', 'xc', and 'x'.
Bugs Fixed:
o magick/effect.c: Should now compile for ARM CPU.
o TIFF: Don't request Kodak private tags since these cause some
versions of libtiff to misbehave.
o When performing string expansion of image attribute identifiers, skip
those which require access to image pixels if image pixels are not
present.
o CropImageToHBITMAP(), ImageToHBITMAP(): Fix leak of bitmap handle.
Thanks,
Bob
======================================
Bob Friesenhahn
[email protected], http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer, http://www.GraphicsMagick.org/
-------------------------------------------------------------------------
This SF.net email is sponsored by the 2008 JavaOne(SM) Conference
Don't miss this year's exciting event. There's still time to save $100.
Use priority code J8TL2D2.
http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone