ImageMagickpopen_utf8 command injection vulnerability report Author: niubl (know Chuangyu 404 Security Lab) Date: I. Vulnerability Summary I. vulnerability description
ImageMagick is a widely used image processing program. many manufacturers call this program for image processing, including scaling, cutting, watermarking, and format conversion. I found that when users pass in a file name that contains | vertical bars, the command injection vulnerability may be triggered.
Ii. vulnerability impact
Test: ImageMagick-7.0.1-2.tar.bz2
Iii. Vulnerability Analysis
ImageMagick calls the OpenBlob () function when processing the file name. in the OpenBlob () function, Line 1 of the code determines whether the file name starts with a vertical line. If yes, then he will call the popoen_utf8 () function to process the file name, code
To the popoen_utf8 () function, the popen_utf8 () function call will call the popen () function to open the file, so that we can inject system commands and code
Iv. vulnerability exploitation (PHP)
When PHP disables the execution of system command functions, we can use it to bypass disable_funtion. PHP writes the following code:
Run the command in PHP.
II. Solution
The official code has been updated to Gitlab, but the final fix version has not yet been released. the patch details can be found at the following link:
- Http://git.imagemagick.org/repos/ImageMagick/commit/40639d173aa8c76b850d625c630b711fee4dcfb
- Http://git.imagemagick.org/repos/ImageMagick/commit/4674b3e1ea87a69646a6dbac8772c45eeb20c9f0
III. vulnerability timeline
2016.05.07 found this vulnerability in Chuangyu 404 security lab niubl
Foreign investigator reports and published vulnerability details http://permalink.gmane.org/gmane.comp.security.oss.general/19669
Release Analysis report