Gentoo Archives: gentoo-user

From: Peter Humphrey <peter@××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] ImageMagick-7 security
Date: Thu, 23 Aug 2018 08:12:15
Message-Id: 1928790.JmGX2YgDP1@peak
In Reply to: [gentoo-user] ImageMagick-7 security by Mick
1 On Thursday, 23 August 2018 09:06:12 BST Mick wrote:
2 > I noticed this enotice in imagemagick:
3 >
4 > * For security reasons, a policy.xml file was installed in
5 > /etc/ImageMagick-7 * which will prevent the usage of the following coders
6 > by default: *
7 > * - PS
8 > * - EPS
9 > * - PDF
10 > * - XPS
11 >
12 > Excuse my ignorance, but I am not sure why the above PS related files are
13 > disabled. What is the security threat exactly? JavaScript contents which
14 > may be executed by ImageMagick?
15
16 That prompted me to emerge -K imagemagick, and I saw the same. But just
17 before the line " * For security reasons..." was this:
18
19 /var/tmp/portage/media-gfx/imagemagick-7.0.8.10-r1/temp/environment: line
20 2260: version_is_at_least: command not found
21
22 So that's two mysteries.
23
24 --
25 Regards,
26 Peter.

Replies

Subject Author
Re: [gentoo-user] ImageMagick-7 security "Corentin “Nado” Pazdera" <nado@××××××××××.be>