GraphicsMagick Security Alert

Bob Friesenhahn <[email protected]> Thu, 5 Nov 2009 18:35:17 -0600 (CST)
Newsgroups gmane.comp.video.graphicsmagick.announce
Message-ID <[email protected]>
There is a potential security exploit with certain configurations of 
the Unix/MinGW/Cygwin "modules" build of GraphicsMagick.  The issue is 
in libltdl rather than GraphicsMagick, but certain build 
configurations of GraphicsMagick expose the potential exploit.  Some 
operating systems will still be reasonably secure while others are 
quite risky.

If this command produces no output then you are likely ok:

   gm -version | grep with-modules | grep disable-static

If it does output a line of text then there may be a security risk.

To be safe from the risk while using a modules build then make sure 
that GraphicsMagick is configured with these options:

   --enable-shared --disable-static --with-modules

People using really anchient versions of GraphicsMagick with terse 'gm 
-version' output will need to use other means to see if 
--disable-static was used.

Thanks,

Bob
--
Bob Friesenhahn
[email protected], http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july