7 ms·
GraphicsMagick and ImageMagick popen() shell vulnerability via filename
- zerocrates 10y agoThe particularly troublesome part of this issue (and the previous big one) is the interaction between all the "power" ImageMagick provides in its filename parsing and its MVG and SVG decoders. You'd think that just having applications not use user-provided filenames during the conversion process would prevent much of what's been disclosed lately, but no: the MVG decoder exposes all those features to a user that merely controls the content of the input file. The mitigations from the last big vulnerability will still work against this, but people who merely updated to an ImageMagick that fixed the curl command escaping would be in trouble.
- userbinator 10y agoThe biggest question I have is why filenames would even need to be treated specially by ImageMagick anyway. Almost all command-line utilities that are designed to be used in pipelines have the convention of using stdin/stdout, and do so without requiring they spawn shells themselves.
- zerocrates 10y ago"Why?" can be an interesting question with ImageMagick. Does it need a prefix you can put on a filename that makes the file automatically get deleted after it's read? I don't think so, but there it is.
- ams6110 10y agoAt some point in the past, someone thought it would be clever.
- 0942v8653 10y agoWow. This is really scary. Especially the SVG issue. Is it common to support xlink:href on servers that use ImageMagick? It seems like that would allow you to read any readable image on the FS anyway, which is a vulnerability in itself.
- zerocrates 10y ago> It seems like that would allow you to read any readable image on the FS anyway, which is a vulnerability in itself. It does. You can trivially use the same feature to render the contents of a readable text file into the output image, too.
- wfunction 10y ago> The simple solution to the problem is to disable the popen support (HAVE_POPEN) Is it just me or is this the wrong way to tackle this? The question to me is why the file name being interpreted in some way in the first place, not why popen is being used on the result of the interpretation. Also, why are pipes even being allowed in the file name in the first place? (I'm asking about POSIX/*nix here, not about ImageMagick.)
- AgentME 10y agoLinux allows any byte to be a part of a filename except for the null byte and '/'. It's not the kernel or filesystem's fault if some program like sh treats some characters like '|' specially.
- rtpg 10y agoBut I don't get why you need to use the shell to get your file? If you have a filename maybe you should manipulate the file directly instead of delegating to the shell.
- lloeki 10y agoInterestingly enough, Cocoa on OS X allows '/' but disallows ':', and maps them back and forth when going down to the Darwin layer, as ':' used to be the (always invisible in the UI) path separator pre-OS X.
- bigiain 10y agoI'm wondering now if you're as old as I am (old enough to have written code for OS9), or if you're younger but curious about archeological wierdnesses in modern OSs...
- Bromskloss 10y ago> why are pipes even being allowed in the file name in the first place? Why not? It's a perfectly legitimate (printable) character. The filesystem can't know that one shell or another will come along and use it (and several other characters) for special purposes. I go the opposite way and rather question why slashes aren't allowed. Non-printable characters, though, I think we could do without them. Put differently, I think it makes sense to let filenames consist of characters, rather than of bytes.
- 0x0 10y agoSo, just like Perl?
- joosters 10y agoOnly badly-written perl. It's a bit like claiming that SQL allows for SQL injection attacks.
- 0x0 10y agoWell, the default open() method do perform pipe execs if you prepend or append "|", just like here. http://docstore.mik.ua/orelly/perl3/prog/ch16_03.htm http://docstore.mik.ua/orelly/perl3/prog/ch16_03.htm
- labster 10y agoIf you're not using two-argument open() in Perl 5, you deserve what you get.
- sebcat 10y agoIf you're not using fork, dup2, execve instead of popen, you deserve what you get.
- bigiain 10y ago"If you're not using two-argument open() in Perl 5, you deserve what you get." Pretty sure that's not quite what you meant to say... http://modernperlbooks.com/mt/2010/04/three-arg-open-migrating-to-modern-perl.html http://modernperlbooks.com/mt/2010/04/three-arg-open-migrati... If you _are_ using two-arg open, or if you're _not_ using three-arg open. (Or, the more general case: "If you're using Perl you deserve what you get - if you don't understand all the language features you're using." (And feel free to substitute whatever language will start the argument in place of Perl in that claim...)
- joosters 10y agoTo be fair, I agree there's some bad code in there, and no real mention of any security concerns. Not good!
- trollian 10y agoWho on earth still uses ImageMagick? Security holes in it are old news. Like 15 year old news.
- Bromskloss 10y agoWhat replacement would you suggest?
- tobltobs 10y agoLibvips. It also doesn't choke on large files and doesn't fill your tmp dir with GBs large tempfiles.
- mappu 10y agoMost basic image manipulation can be performed using only the standard library packages, if your language includes such (PHP's bundled `libgd2` fork / Golang's `image` package / Qt QImage+QPixMap ). For Python `pillow` is popular.
- harryf 10y agoPython / Pillow (formerly PIL) could offer a real path here although there's a gap to Imagemagick on things like SVG
- mschuster91 10y agoI believe php uses imagick under the hood, and even if it does not, I'd rather rely on imagick than on PHP code when accepting exotic formats.
- voltagex_ 10y agoFrom a security standpoint, wouldn't it be better to rely on PHP (first)? Are you more or less likely to get RCE from PHP or ImageMagick? I'd say PHP has had a lot more eyes on it, security wise.
- voltagex_ 10y agoThe current situation reminds me of OpenSSL after Heartbleed - researchers start paying lots of attention and finding other issues after the "main" one. Sad that this is what it takes for a big, old project like ImageMagick to get some TLC.
- ndj7 10y agoThere's a crucial difference; OpenSSL was designed to be secure. ImageMagick was designed to support hundreds of codecs and thousands of operations. You can't pivot design on 1.25 million lines of code (est.) very quickly after 25 years of feature-first development process. I'm a bit skeptical it will happen at all; it would be a multi-million dollar undertaking. Better to describe its design scope and tradeoffs, and get people to use it properly - sandbox it if it's on the server. I started Imageflow to solve that problem - a server-focused design with strict design rules: security is first, followed by visual quality, followed by performance. We've kept the codebase to just 10kloc and we are 50% feature complete, but need to get a lot more momentum on Kickstarter to make completion possible. See https://www.imageflow.io https://www.imageflow.io
- _jomo 10y agoThanks HN, I have now lost my Twitter profile image and can't upload a new one: https://twitter.com/_jom0/status/737081667215601664 https://twitter.com/_jom0/status/737081667215601664
- keyle 10y agoI love that you did that. Never be afraid of breaking things. In this case it's amusing but imagine you would have done this in a banking application and you'd probably be arrested for hacking.
- bigiain 10y agohttps://twitter.com/ajlobster/status/735240869859753985 https://twitter.com/ajlobster/status/735240869859753985 :-)
- Bromskloss 10y agoI always have a hard time interpreting Twitter posts. Did you link to two images in this post? Were they things you observed when trying to upload an avatar with a filename in accordance with this bug? Why does Twitter crop the images? (This it what I see: https://u.pomf.is/dmomwl.png https://u.pomf.is/dmomwl.png )
- _jomo 10y agoYes, there are two images. You should be able to click on them separately to open the full images [0][1]. The first screenshot shows a preview of the file with its name which I tried to upload to Twitter, the other one shows what I observed locally through htop when running `convert` on that filename. 0: https://pbs.twimg.com/media/Cjqj3oiXIAAYJix.jpg:large https://pbs.twimg.com/media/Cjqj3oiXIAAYJix.jpg:large 1: https://pbs.twimg.com/media/Cjqj3pFWkAEaRcD.jpg:large https://pbs.twimg.com/media/Cjqj3pFWkAEaRcD.jpg:large
- yAnonymous 10y agoLet's check how much HDD space they got? |dd if=/dev/zero of=hello.txt bs=1M count=1000000000
- Mojah 10y agoIn case anyone is interested, here's another mirror of the CVE: https://marc.ttias.be/oss-security/2016-05/msg00255.php https://marc.ttias.be/oss-security/2016-05/msg00255.php
- kyledrake 10y agoDoes this affect non-SVG (and other weird format I've never heard of) images? (such as jpg, png, bmp, gif) I'm trying to figure out a way to patch this that doesn't involve recompiling imagemagick. Like most people I get it from dist, compiling it is kindof a PITA.
- yxhuvud 10y agoThis is not the first time popen with | has led to security issues. At the same time it doesn't have any legitimate use cases that I can think of. Is there any good reason to not patch popen and remove the support for |s instead?
- MereInterest 10y agoIt can be useful if you want to offload some of the processing to other processes. // Open a gzipped file, display progress bar snprintf(buf, sizeof(buf), "pv %s | zcat", filename); FILE* f = popen(buf, "r"); // Add an additional processing step when reading file FILE* f = NULL; if(do_extra_step) { snprintf(buf, sizeof(buf), "zcat %s | extra_step", filename); f = popen(buf, "r"); } else { snprintf(buf, sizeof(buf), "zcat %s", filename); f = popen(buf, "r"); } The first example could be replicated by using zlib and reproducing pv's progress bar in-app. More work, but nothing especially tricky about it. For the second example, it would be more difficult, for two reasons. First, popen() can open either a read or a write pipe, but not both. In order to write to extra_step's stdin, then read from stdout, you'll need to switch over to fork/exec. Second, you'll have to handle all the buffering between zcat and extra_step yourself, rather than getting it for free.
- 0xmohit 10y agoUnfortunately, this is not the only one. In fact, there are so many that there is a dedicate site: https://imagetragick.com/ https://imagetragick.com/ It also contains several PoC.