ImageMagickpopen_utf8 command injection vulnerability report

Source: Internet
Author: User
ImageMagickpopen_utf8 command injection vulnerability report Author: niubl (know Chuangyu 404 Security Lab) Date: I. Vulnerability Summary I. vulnerability description

ImageMagick is a widely used image processing program. many manufacturers call this program for image processing, including scaling, cutting, watermarking, and format conversion. I found that when users pass in a file name that contains | vertical bars, the command injection vulnerability may be triggered.

Ii. vulnerability impact

Test: ImageMagick-7.0.1-2.tar.bz2

Iii. Vulnerability Analysis

ImageMagick calls the OpenBlob () function when processing the file name. in the OpenBlob () function, Line 1 of the code determines whether the file name starts with a vertical line. If yes, then he will call the popoen_utf8 () function to process the file name, code

To the popoen_utf8 () function, the popen_utf8 () function call will call the popen () function to open the file, so that we can inject system commands and code

Iv. vulnerability exploitation (PHP)

When PHP disables the execution of system command functions, we can use it to bypass disable_funtion. PHP writes the following code:

 

Run the command in PHP.

II. Solution

The official code has been updated to Gitlab, but the final fix version has not yet been released. the patch details can be found at the following link:

  • Http://git.imagemagick.org/repos/ImageMagick/commit/40639d173aa8c76b850d625c630b711fee4dcfb
  • Http://git.imagemagick.org/repos/ImageMagick/commit/4674b3e1ea87a69646a6dbac8772c45eeb20c9f0
III. vulnerability timeline

2016.05.07 found this vulnerability in Chuangyu 404 security lab niubl

Foreign investigator reports and published vulnerability details http://permalink.gmane.org/gmane.comp.security.oss.general/19669

Release Analysis report

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.