Topic on Project:Support desk

Recent ImageMagick security bug on MW?

3
Subfader (talkcontribs)
87.123.63.222 (talkcontribs)

MediaWiki is not made to work around bugs in third party software. No one will guarantee you that a malicious upload through MediaWiki definitely cannot trigger this vulnerability. Especially when specially crafted files are used, attackers may find ways to exploit an open vulnerability, maybe even if MediaWiki in the end does not allow their upload, so that the actual upload inside MediaWiki does not succeed.

The only right solution is to use a fixed version of ImageMagick!

Subfader (talkcontribs)

Yes, of course. Chances could have been it renames the file before it is passed to IM. ;)

Reply to "Recent ImageMagick security bug on MW?"