Re: Sufficient patch for CVE-2005-4601?

Daniel Kobras <[email protected]> Wed, 1 Mar 2006 17:17:47 +0100
Newsgroups gmane.comp.video.graphicsmagick.core
Message-ID <[email protected]>
On Wed, Mar 01, 2006 at 09:54:29AM -0600, Albert Chin wrote:
> Is the attached patch ok for CVE-2005-4601? It is taken from the
> Debian patch for ImageMagick 5.4.4.5.

It's an easy band-aid for metacharacters in current shells but doesn't
fix the underlying problem. The patch from unstable for both ImageMagick
and GraphicsMagick solves it on a more fundamental level without
restricting allowed usernames, but needs polishing for systems without
symlink support. ImageMagick SVN has a universal implementation based on
the Debian patch, but I haven't ported it GraphicsMagick yet.

Regards,

Daniel.



-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642