« CSRF - An underestimated attack method | Main | My talk at the RubyFools Conference »
Sunday
Apr202008

ImageMagick security advisory

A security advisory has been released for libpng, the "official PNG reference library". Libpng is used by ImageMagick, "a software suite to create, edit, and compose bitmap images". Some Rails applications use it to convert, resize or to create thumbnails. The original security advisory was issued by oCERT:

Applications using libpng that install unknown chunk handlers, or copy unknown chunks, may be vulnerable to a security issue which may result in incorrect output, information leaks, crashes, or arbitrary code execution. The issue involves libpng incorrectly handling zero length chunks which results in uninitialized memory affecting the control flow of the application.

The security advisory from libpng reads:

We believe this is a rare circumstance. It occurs in "pngtest" that is a part of the libpng distribution, in pngcrush, and in recent versions of ImageMagick (6.2.5 through 6.4.0-4). We are not aware of any other vulnerable applications. 

And here is the CVE:

libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero length "unknown" chunks, which trigger an access of uninitialized memory.
 
Although the impacts are not clear, it is advisable to update ImageMagick, the current version is 6.4.0-7.

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments (4)

Hi I am really impressed with this Blog. Now a days Ruby on Rails is really very popular and Ruby on rails is A Powerful Web Development Frame Work. To know more about Ruby on Rails visit http://www.rightwaysolution.com/ruby_on_rails_customization.html. This will help to know more about ROR

May 26, 2008 | Unregistered CommenterRoshan

Thank you for sharing such good experience.I also like to write such things in own blog. Our iwc repicas

August 25, 2010 | Unregistered CommenterEunice J. Garner

Solar Power Charger techniques have seen considerable progress, solar power from hot water, heating and other building extensions to the industrial and agricultural production in many sectors

August 29, 2010 | Unregistered Commenterjing

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>