Re: Patches for security issues and other problems.
Bob Friesenhahn <[email protected]> Tue, 3 Jan 2006 16:27:16 -0600 (CST)
| Newsgroups | gmane.comp.video.graphicsmagick.bugs |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 3 Jan 2006, Daniel Kobras wrote: > * CAN-2005-0397 (Format string vulnerability in magick/image.c) > Was originally reported against ImageMagick 6.x because the affected > function had been renamed, but also needs to be fixed in 5.x and > GraphicsMagick. Patch against 1.1.7 attached. The chunk of code being patched is indeed known to be broken. The proposed patch simply breaks it even more. It really was intended that image_info->filename contain a printf style specification since the code is testing to see if there is a %d specification in the filename which can be substituted. The GM 1.2 TODO file mentions that a filename specification like "logo%n.png" crashes GM. Bob ====================================== Bob Friesenhahn [email protected], http://www.simplesystems.org/users/bfriesen/ GraphicsMagick Maintainer, http://www.GraphicsMagick.org/ ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click