Quantcast
Channel: magick Discussions Rss Feed
Viewing all articles
Browse latest Browse all 3693

New Post: ImageMagick Security Issue

$
0
0
Looking at the vulnerability disclosure, there are five issues:
  1. CVE-2016-3714: Remote code execution via command injection
  2. CVE-2016-3715: Arbitrary file delete
  3. CVE-2016-3716: Arbitrary file move
  4. CVE-2016-3717: Arbitrary file read
  5. CVE-2016-3718: Arbitrary HTTP/FTP GET requests
I see that your policy.xml change on Tuesday added the recommended entry to block indirect reads (issue #4 above).

Could you elaborate on how 1, 2, 3, and 5 have been mitigated in Magick.NET?

Viewing all articles
Browse latest Browse all 3693

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>