ImageTragick turns image files into commands
Summary
An ImageMagick vulnerability allows prepared images to execute shell commands on servers via unsafe delegate calls. The hole was disclosed in May 2016. It affected widely used ImageMagick versions.
Ideas
- ImageMagick delegates certain formats to external programs.
- File contents could end up unfiltered in shell commands.
- Upload functions made the hole remotely reachable.
- File extensions did not prevent dangerous pseudo-formats from being interpreted.
Insights
- Media processing is active parsing of untrusted data.
- External tools extend capabilities and the attack surface at the same time.
- Sandboxing limits damage even with unknown parser bugs.
Facts
- Several CVE numbers described variants.
Recommendations
- Update ImageMagick and restrict the permitted formats.
- Process uploads without network access and unnecessary privileges.
References
Links to the original source and the Web Archive open in a new tab.