Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] ImageMagick-7 security
Date: Thu, 23 Aug 2018 08:06:26
Message-Id: 4587596.zHbW9HnCAH@dell_xps
1 I noticed this enotice in imagemagick:
2
3 * For security reasons, a policy.xml file was installed in /etc/ImageMagick-7
4 * which will prevent the usage of the following coders by default:
5 *
6 * - PS
7 * - EPS
8 * - PDF
9 * - XPS
10
11 Excuse my ignorance, but I am not sure why the above PS related files are
12 disabled. What is the security threat exactly? JavaScript contents which may
13 be executed by ImageMagick?
14
15 --
16 Regards,
17 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
[gentoo-user] Re: ImageMagick-7 security Mick <michaelkintzios@×××××.com>
Re: [gentoo-user] ImageMagick-7 security Peter Humphrey <peter@××××××××××××.uk>
[gentoo-user] Re: ImageMagick-7 security Ian Zimmerman <itz@××××××××××××.org>