Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 19 May 2016 20:00:37 +0100
From: Simon McVittie <smcv@...ian.org>
To: oss-security@...ts.openwall.com
Subject: Re: ImageMagick Is On Fire -- CVE-2016-3714

On Thu, 19 May 2016 at 12:25:09 -0600, Kurt Seifried wrote:
> Without making a commercial pitch for the company I work ... I suspect one
> aspect of other vendors not fixing this is that there is a very
> simple/effective/verifiable workaround to prevent exploitation of this

Having looked into it a bit for Debian, there are several factors:

* mitigations exist, like you said

* many of the upstream fixes in ImageMagick are not clearly separated
  from random other changes (I found one in a commit labelled
  "Update to the latest autoconf / automake"!)

* many of the upstream fixes in ImageMagick (and GraphicsMagick)
  are really just mitigations too, and they remove features that someone
  could conceivably have been using, which rather goes against the idea
  of a stable release with a fixed feature-set
  (yes, I realise some of those features cannot be done securely)

* there are a large number of other issues found via fuzzing, in coders
  for miscellaneous formats that you'll probably never see "in the wild",
  which could conceivably also be security vulnerabilities but probably
  aren't feasible to backport to old releases

Bob, if you would like distributions to pick up GraphicsMagick security
fixes in a timely way, it would probably be really useful to do an
upstream release - distributions are typically a lot more confident about
backporting large changes to their stable branches without regressions
if they've been able to get some testing on the same changes in their
unstable branches first.

    S

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.