5 ms·
Another one rce: https://blog.vulnspy.com/2018/10/23/jQuery-File-Upload-9-x-Remote-Code-Execution-With-ImageMagick-Ghostscript/ https://blog.vulnspy.com/2018/10
by ambulong 8y ago
Another one rce: https://blog.vulnspy.com/2018/10/23/jQuery-File-Upload-9-x-Remote-Code-Execution-With-ImageMagick-Ghostscript/ https://blog.vulnspy.com/2018/10/23/jQuery-File-Upload-9-x-R...
- blueimp 8y agoSince this is about vulnerabilities in a third-party dependency (ImageMagick/Ghostscript), the recommendation in the blog post to use the GD library instead (what the image_library 0 setting does) is not very sound, as libgd also had a number of vulnerabilities in the past, albeit less than ImageMagick: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Libgd https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Libgd A better recommendation is to securely configure ImageMagick, or even better: to use a safer image processing library (e.g libvips or imageflow). I’ve added some mitigating code and recommendations on how to securely configure ImageMagick to jQuery File Upload, please have a look here: https://github.com/blueimp/jQuery-File-Upload/blob/master/VULNERABILITIES.md#potential-vulnerabilities-with-php-imagemagick https://github.com/blueimp/jQuery-File-Upload/blob/master/VU... https://github.com/blueimp/jQuery-File-Upload/blob/master/SECURITY.md#secure-image-processing-configurations https://github.com/blueimp/jQuery-File-Upload/blob/master/SE...