Menu
Critical flaws in ImageMagick library expose websites to hacking

Critical flaws in ImageMagick library expose websites to hacking

The flaws can be exploited through specially crafted images to execute malicious code on Web servers

A tool used by millions of websites to process images has several critical vulnerabilities that could allow attackers to compromise Web servers. To make things worse, there's no official patch yet and exploits are already available.

The vulnerabilities were discovered by Nikolay Ermishkin from the Mail.Ru security team and were reported to the ImageMagick developers who attempted a fix in version 6.9.3-9, released on April 30. However, the fix is incomplete and the vulnerabilities can still be exploited.

Furthermore, there is evidence that people aside from security researchers and  ImageMagick developers know about the flaws, which is why their existence was publicly disclosed Tuesday. The flaws can be exploited by uploading specially crafted images to Web applications that rely on ImageMagick to process them.

ImageMagick is a command-line tool that can be used to create, edit and convert a large number of image file formats. Its library is the base for other Web server packages like PHP’s imagick, Ruby’s rmagick and papercli and Node.js’s imagemagick.

Since the public disclosure Tuesday, security researchers have already developed proof-of-concept exploits for the issues. This means that attackers could too, increasing the likelihood of malicious in-the-wild attacks.

Security researchers have dubbed the set of flaws ImageTragick and created a website with more information for website developers and administrators, including mitigation advice until a complete patch is made available.

"Verify that all image files begin with the expected 'magic bytes' corresponding to the image file types you support before sending them to ImageMagick for processing," the researchers said on the website. "Use a policy file to disable the vulnerable ImageMagick coders. The global policy for ImageMagick is usually found in '/etc/ImageMagick'."

The ImageMagick developers have also suggested the policy-based mitigation and posted an example policy file on their support forum.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Featured

Slideshows

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners

More than 500 channel leaders gathered in Auckland on 21 October at the ​Reseller News Innovation Awards ​2020 to celebrate the achievements of the New Zealand technology industry's top partners, start-ups, vendors, distributors and individuals.

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners
Meet the winners of the 2020 Reseller News Innovation Awards

Meet the winners of the 2020 Reseller News Innovation Awards

Reseller News honoured the standout players of the New Zealand channel in front of more than 500 technology leaders in Auckland on 21 October, recognising the achievements of top partners, start-ups, vendors, distributors and individuals.

Meet the winners of the 2020 Reseller News Innovation Awards
Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Show Comments