Wedge

Public area => The Pub => Bug reports => Topic started by: CerealGuy on May 4th, 2016, 12:57 PM

Title: [Critical?] ImageMagick exploit
Post by: CerealGuy on May 4th, 2016, 12:57 PM
Didn't test it yet, i'm using GD2 but people with imagemagick should have a look at their servers maybe.
https://www.imagemagick.org/discourse-server/viewtopic.php?t=29588

Workarounds(?!):
- use GD2
- add imagemagick policies/wait for fix
- disable avatars/file attachements
Title: Re: [Critical?] ImageMagick exploit
Post by: Nao on July 19th, 2016, 10:29 AM
Thanks for the heads-up! Can't really do anything on my side, short of disabling IM support entirely...