Critical Security Flaw in ImageMagick (imagetragick)

A vulnerability with a widely deployed image processing library was disclosed on the 5th of May 2016. Within an hour of the disclosure AppCheck NG was updated to detect the flaw. A Practical View of the Most Common Threats Facing Web Apps Today The Web Application Security seminar is a free event that presents a detailed analysis of the most common threats facing web applications today. We will review high profile examples and provide a technical breakdown of critical security flaws along with an introduction into emerging technologies such as HTML5. Each candidate will receive a copy of the slides and exclusive tools and exploit code used in the live hacking demonstrations.

A vulnerability with a widely deployed image processing library was disclosed on the 5th of May 2016. Within an hour of the disclosure.

AppCheck was updated to detect the flaw.

 

From the original advisory:

“There are multiple vulnerabilities in ImageMagick, a package 
commonly used by web services to process images. One of the vulnerabilities
can lead to remote code execution (RCE) if you process user submitted images. 
The exploit for this vulnerability is being used in the wild.
A number of image processing plugins depend on the ImageMagick library, 
including, but not limited to, PHP’s imagick, Ruby’s rmagick and paperclip, and nodejs’s imagemagick.”

 

Full details of the flaw can be found at https://imagetragick.com/

Get started with Appcheck

No software to download or install.

Contact us or call us 0113 887 8380

About Appcheck

AppCheck is a software security vendor based in the UK, offering a leading security scanning platform that automates the discovery of security flaws within organisations websites, applications, network and cloud infrastructure. AppCheck are authorized by te Common Vulnerabilities and Exposures (CVE) Program aas a CVE Numbering Authority (CNA)

No software to download or install.
Contact us or call us 0113 887 8380

Start your free trial

Your details
IP Addresses
URLs

Get in touch