Re: GraphicsMagick 1.1.8 release needed
Bob Friesenhahn <[email protected]> Mon, 11 Sep 2006 14:16:36 -0500 (CDT)
| Newsgroups | gmane.comp.video.graphicsmagick.core |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 11 Sep 2006, Albert Chin wrote: >> I am not aware of any outstanding security issues related to PNG. >> ImageMagick security issues do not necessarily exist in >> GraphicsMagick. Is there a security issue I should be aware of? > > Do any of these affect GraphicsMagick? > CVE-2005-4601 Yes. The existing solutions are not appropriate since they simply deny using a large number of valid filenames and don't actually address the underlying problem. Breaking normal use is not acceptable. > CVE-2006-0082 Somewhat. It is possible to crash GraphicsMagick with a carefully-crafted output filename but I don't see any way to inject code. Many of the suggested fixes I have seen for this issue actually disable intended functionality. > CVE-2006-2440 I can't say for sure without knowing details of the exploit. The ExpandFilenames function has been re-written in GraphicsMagick. Much of the globbing code has been rewritten as well. > CVE-2006-3743 A patch was just added to GM HEAD today for this issue. It should be in the 1.1 branch soon. > CVE-2006-3744 It looks like this one probably does apply. It would help if package maintainers were notified of these issues along with enough information to solve them, but it seems that package maintainers are the last to know. Bob ====================================== Bob Friesenhahn [email protected], http://www.simplesystems.org/users/bfriesen/ GraphicsMagick Maintainer, http://www.GraphicsMagick.org/ ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642