bk99.de entertain the web since 1997

ImageTragick turns image files into commands

Summary

An ImageMagick vulnerability allows prepared images to execute shell commands on servers via unsafe delegate calls. The hole was disclosed in May 2016. It affected widely used ImageMagick versions.

Ideas

  • ImageMagick delegates certain formats to external programs.
  • File contents could end up unfiltered in shell commands.
  • Upload functions made the hole remotely reachable.
  • File extensions did not prevent dangerous pseudo-formats from being interpreted.

Insights

  • Media processing is active parsing of untrusted data.
  • External tools extend capabilities and the attack surface at the same time.
  • Sandboxing limits damage even with unknown parser bugs.

Facts

  • Several CVE numbers described variants.

Recommendations

  • Update ImageMagick and restrict the permitted formats.
  • Process uploads without network access and unnecessary privileges.

References

Read the original article

Search the Web Archive