Gentoo Archives: gentoo-user

From: Ian Zimmerman <itz@××××××××××××.org>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: ImageMagick-7 security
Date: Thu, 23 Aug 2018 15:19:35
Message-Id: 20180823151919.mnw5ppw7sa27x7p3@matica.foolinux.mooo.com
In Reply to: [gentoo-user] ImageMagick-7 security by Mick
1 On 2018-08-23 09:06, Mick wrote:
2
3 > * For security reasons, a policy.xml file was installed in
4 > * /etc/ImageMagick-7 which will prevent the usage of the following
5 > * coders by default:
6 > *
7 > * - PS
8 > * - EPS
9 > * - PDF
10 > * - XPS
11
12 IM spawns ghostscript for these formats, and ghostscript is full of
13 holes (so to speak). See following post and its descendants:
14
15 http://www.openwall.com/lists/oss-security/2018/08/21/2
16
17 --
18 Please don't Cc: me privately on mailing lists and Usenet,
19 if you also post the followup to the list or newsgroup.
20 To reply privately _only_ on Usenet and on broken lists
21 which rewrite From, fetch the TXT record for no-use.mooo.com.