oss-sec mailing list archives
Re: ImageMagick Is On Fire -- CVE-2016-3714
From: Simon McVittie <smcv () debian org>
Date: Thu, 19 May 2016 20:00:37 +0100
On Thu, 19 May 2016 at 12:25:09 -0600, Kurt Seifried wrote:
Without making a commercial pitch for the company I work ... I suspect one aspect of other vendors not fixing this is that there is a very simple/effective/verifiable workaround to prevent exploitation of this
Having looked into it a bit for Debian, there are several factors:
* mitigations exist, like you said
* many of the upstream fixes in ImageMagick are not clearly separated
from random other changes (I found one in a commit labelled
"Update to the latest autoconf / automake"!)
* many of the upstream fixes in ImageMagick (and GraphicsMagick)
are really just mitigations too, and they remove features that someone
could conceivably have been using, which rather goes against the idea
of a stable release with a fixed feature-set
(yes, I realise some of those features cannot be done securely)
* there are a large number of other issues found via fuzzing, in coders
for miscellaneous formats that you'll probably never see "in the wild",
which could conceivably also be security vulnerabilities but probably
aren't feasible to backport to old releases
Bob, if you would like distributions to pick up GraphicsMagick security
fixes in a timely way, it would probably be really useful to do an
upstream release - distributions are typically a lot more confident about
backporting large changes to their stable branches without regressions
if they've been able to get some testing on the same changes in their
unstable branches first.
S
Current thread:
- Re: ImageMagick Is On Fire -- CVE-2016-3714, (continued)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Seth Arnold (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Tim (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Brandon Dees (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Seth Arnold (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Seth Arnold (May 03)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Jeremy Stanley (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Kurt Seifried (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Simon McVittie (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 John Lightsey (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Bob Friesenhahn (May 20)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Simon Lees (May 20)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Thomas Klausner (May 19)
- Re: ImageMagick Is On Fire -- CVE-2016-3714 Sven Kieske (May 20)
