oss-sec mailing list archives
Re: ImageMagick Is On Fire -- CVE-2016-3714
From: Simon Lees <sflees () suse de>
Date: Sat, 21 May 2016 08:31:23 +0930
On 05/20/2016 11:22 PM, Bob Friesenhahn wrote:
On Thu, 19 May 2016, John Lightsey wrote:This is the list I'm working off of. For RedHat and Debian, I only checked the ImageMagick updates. CVE-2016-3718 - SSRF via HTTP and FTP coders ImageMagick: Not fixed GraphicsMagick: Not fixed RedHat: Fixed Debian: FixedThe above topic is worthy of discussion. What is a security issue in some contexts is normal and necessary in others.No CVE assigned - Heap overflow in PICT parser ImageMagick: Fixed GraphicsMagick: ?? RedHat: Not fixed Debian: Not fixed Reference: http://www.openwall.com/lists/oss-security/2016/05/11/3The GraphicsMagick development code is not vulnerable to this one. GraphicsMagick may have been vulnerable in the past.No CVE assigned - Out of bounds read in the PSD parser ImageMagick: Fixed GraphicsMagick: ?? RedHat: Not fixed Debian: Not fixed Reference: http://www.openwall.com/lists/oss-security/2016/05/11/3The GraphicsMagick development code is not vulnerable to this one. GraphicsMagick may have been vulnerable in the past.Are there other formats that are unsafe and should be removed using the policy configuration files?In interest of full-disclosure, the GraphicsMagick project has fixed approximately 45 CVE-worthy issues since the last release, not including issues covered by CVE-2016-2317 and CVE-2016-2318 (which are fixed in the development code). Many of the test files are published in full open view on bug trackers or other places. In a similar time-frame, the ImageMagick project has been provided a great many files (likely more than 100) which crash the software and many of these files are published in full open view on bug trackers or other places. Commits and other records show that problems are being fixed. When fixed versions are released, OS distributions which continue to provide 3-year old releases are exposing users to releases with perhaps hundreds of fixed vulnerabilities which can be triggered using publically available files. Bob
Some distro's have customers that pay them to have the 3 year old version with only fixes to bugs as they wish to reduce the chance of breakage. I must thank you the email you published with the list of issues and there corresponding patches made it much much easier to address the issues in GraphicsMagick then it was for ImageMagick. -- Simon Lees (Simotek) http://simotek.net Emergency Update Team keybase.io/simotek SUSE Linux Adeliade Australia, UTC+9:30 GPG Fingerprint: 5B87 DB9D 88DC F606 E489 CEC5 0922 C246 02F0 014B
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- Re: ImageMagick Is On Fire -- CVE-2016-3714, (continued)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Seth Arnold (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Jeremy Stanley (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Kurt Seifried (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Simon McVittie (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 John Lightsey (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 20)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Simon Lees (May 20)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Thomas Klausner (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Sven Kieske (May 20)