Re: GraphicsMagick 1.1.8 release needed

Bob Friesenhahn <[email protected]> Mon, 11 Sep 2006 14:16:36 -0500 (CDT)
Newsgroups gmane.comp.video.graphicsmagick.core
Message-ID <[email protected]>
On Mon, 11 Sep 2006, Albert Chin wrote:
>> I am not aware of any outstanding security issues related to PNG.
>> ImageMagick security issues do not necessarily exist in
>> GraphicsMagick.  Is there a security issue I should be aware of?
>
> Do any of these affect GraphicsMagick?
>  CVE-2005-4601

Yes.  The existing solutions are not appropriate since they simply 
deny using a large number of valid filenames and don't actually 
address the underlying problem.  Breaking normal use is not 
acceptable.

>  CVE-2006-0082

Somewhat.  It is possible to crash GraphicsMagick with a 
carefully-crafted output filename but I don't see any way to inject 
code.  Many of the suggested fixes I have seen for this issue actually 
disable intended functionality.

>  CVE-2006-2440

I can't say for sure without knowing details of the exploit.  The 
ExpandFilenames function has been re-written in GraphicsMagick.  Much 
of the globbing code has been rewritten as well.

>  CVE-2006-3743

A patch was just added to GM HEAD today for this issue.  It should be 
in the 1.1 branch soon.

>  CVE-2006-3744

It looks like this one probably does apply.

It would help if package maintainers were notified of these issues 
along with enough information to solve them, but it seems that package 
maintainers are the last to know.

Bob
======================================
Bob Friesenhahn
[email protected], http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/


-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642