3 ms·
Image and Video codecs come under attack quite often see https://blog.sucuri.net/2016/05/imagemagick-remote-command-execution-vulnerability.html https://blog.su
by nametube 9y ago
Image and Video codecs come under attack quite often see https://blog.sucuri.net/2016/05/imagemagick-remote-command-execution-vulnerability.html https://blog.sucuri.net/2016/05/imagemagick-remote-command-e...
In this context the image manipulation they do with pillow and the underlying libjpeg would be a potential source of vulnerabilities.
- acdha 9y agoSignificantly, it's not just libjpeg but every format supported by Pillow (http://pillow.readthedocs.io/en/3.4.x/handbook/image-file-formats.html http://pillow.readthedocs.io/en/3.4.x/handbook/image-file-fo...) — many of those vulnerabilities have historically been in obscure formats where the implementation has had far less attention than the mainline JPEG or PNG support.
- mintplant 9y agoYep, I remember multiple smaller art-centric sites getting hit in a wave by an ImageMagick RCE vulnerability. Database dumps, full source leaks, the works. Unsure whether it was the one you linked; it seems more recent than I thought.