Cybertrion Systems

[1/5] GraphicsMagick Insecure File Extension Processing

May 2nd, 2008 by
[1/5] GraphicsMagick Insecure File Extension Processing

:A security issue has been reported in GraphicsMagick, which can be exploited by malicious people to bypass certain security restrictions.The security issue is caused due to the improper processing of file extensions and can be exploited to e.g. access X11 or to invoke certain delegate programs.Successful exploitation requires that a user is tricked into processing a malicious file with a specific file extension.The security issue is reported in versions prior to 1.1.12.Solution:Update to version 1.1.12 or later.Provided and/or discovered by:Reported by the vendor.Original Advisory:http://sourceforge.net/project/shownotes.php?release_id=595544

Original post by kapil

[1/5] GraphicsMagick Insecure File Extension Processing

Related Articles:
  • [4/5] GraphicsMagick Multiple Vulnerabilities
  • [2/5] PHP Tidy Extension “tidy_parse_string()” Buffer Overflow
  • [4/5] Rosoft Media Player File Processing Buffer Overflow Vulnerability
  • [2/5] Novell Identity Manager Client Login Extension Information Disclosure
  • [3/5] libarchive pax Extension Header Denial of Service and Buffer Overflow


  • Posted in Advisories - Exploits | | [1/5] GraphicsMagick Insecure File Extension Processing

    << [2/5] AstroCam “picfile” Cross-Site Scripting Vulnerability | [3/5] vlbook Cross-Site Scripting and Local File Inclusion >>