1 |
On 2018-08-23 09:06, Mick wrote: |
2 |
|
3 |
> * For security reasons, a policy.xml file was installed in |
4 |
> * /etc/ImageMagick-7 which will prevent the usage of the following |
5 |
> * coders by default: |
6 |
> * |
7 |
> * - PS |
8 |
> * - EPS |
9 |
> * - PDF |
10 |
> * - XPS |
11 |
|
12 |
IM spawns ghostscript for these formats, and ghostscript is full of |
13 |
holes (so to speak). See following post and its descendants: |
14 |
|
15 |
http://www.openwall.com/lists/oss-security/2018/08/21/2 |
16 |
|
17 |
-- |
18 |
Please don't Cc: me privately on mailing lists and Usenet, |
19 |
if you also post the followup to the list or newsgroup. |
20 |
To reply privately _only_ on Usenet and on broken lists |
21 |
which rewrite From, fetch the TXT record for no-use.mooo.com. |