Menu
Critical flaws in ImageMagick library expose websites to hacking

Critical flaws in ImageMagick library expose websites to hacking

The flaws can be exploited through specially crafted images to execute malicious code on Web servers

A tool used by millions of websites to process images has several critical vulnerabilities that could allow attackers to compromise Web servers. To make things worse, there's no official patch yet and exploits are already available.

The vulnerabilities were discovered by Nikolay Ermishkin from the Mail.Ru security team and were reported to the ImageMagick developers who attempted a fix in version 6.9.3-9, released on April 30. However, the fix is incomplete and the vulnerabilities can still be exploited.

Furthermore, there is evidence that people aside from security researchers and  ImageMagick developers know about the flaws, which is why their existence was publicly disclosed Tuesday. The flaws can be exploited by uploading specially crafted images to Web applications that rely on ImageMagick to process them.

ImageMagick is a command-line tool that can be used to create, edit and convert a large number of image file formats. Its library is the base for other Web server packages like PHP’s imagick, Ruby’s rmagick and papercli and Node.js’s imagemagick.

Since the public disclosure Tuesday, security researchers have already developed proof-of-concept exploits for the issues. This means that attackers could too, increasing the likelihood of malicious in-the-wild attacks.

Security researchers have dubbed the set of flaws ImageTragick and created a website with more information for website developers and administrators, including mitigation advice until a complete patch is made available.

"Verify that all image files begin with the expected 'magic bytes' corresponding to the image file types you support before sending them to ImageMagick for processing," the researchers said on the website. "Use a policy file to disable the vulnerable ImageMagick coders. The global policy for ImageMagick is usually found in '/etc/ImageMagick'."

The ImageMagick developers have also suggested the policy-based mitigation and posted an example policy file on their support forum.


Follow Us

Join the newsletter!

Error: Please check your email address.

Featured

Slideshows

Kiwi channel closes 2017 with After Hours

Kiwi channel closes 2017 with After Hours

The channel in New Zealand came together to celebrate the close of 2017, as the final After Hours played out in front of a bumper Auckland crowd.

Kiwi channel closes 2017 with After Hours
Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP honoured leading partners across the channel at the Partner Awards 2017 in New Zealand, recognising excellence across the entire print and personal systems portfolio.

Meet the top performing HP partners in NZ
Tech industry comes together as Lexel celebrates turning 30

Tech industry comes together as Lexel celebrates turning 30

Leading figures within the technology industry across New Zealand came together to celebrate 30 years of success for Lexel Systems, at a milestone birthday occasion at St Matthews in the City.​

Tech industry comes together as Lexel celebrates turning 30
Show Comments