libpng vulnerability found on Nov 18

Post any defects you find in the released or beta versions of the ImageMagick software here. Include the ImageMagick version, OS, and any command-line required to reproduce the problem. Got a patch for a bug? Post it here.
Post Reply
henry
Posts: 5
Joined: 2015-11-19T14:47:30-07:00
Authentication code: 1151

libpng vulnerability found on Nov 18

Post by henry »

Recently there was a vulnerability found in all libpng versions up to 1.6.18.
Is there any plan for imageMagick to use libpng 1.6.19?

Thanks
Henry
User avatar
dlemstra
Posts: 1570
Joined: 2013-05-04T15:28:54-07:00
Authentication code: 6789
Contact:

Re: libpng vulnerability found on Nov 18

Post by dlemstra »

As stated here: viewtopic.php?f=3&t=28674, ImageMagick is not vulnerable to CVE-2015-8126. We did however upgrade the libpng version that we link with on Windows.
.NET + ImageMagick = Magick.NET https://github.com/dlemstra/Magick.NET, @MagickNET, Donate
henry
Posts: 5
Joined: 2015-11-19T14:47:30-07:00
Authentication code: 1151

Re: libpng vulnerability found on Nov 18

Post by henry »

Thank you for the reply. I download imageMagick 6.9.2-6 source for windows and found the png version is still 1.6.17. Which version of imageMagick was upgraded to libpng 1.6.19?(Which solve the vulnerable problem).

Thanks
henry
User avatar
dlemstra
Posts: 1570
Joined: 2013-05-04T15:28:54-07:00
Authentication code: 6789
Contact:

Re: libpng vulnerability found on Nov 18

Post by dlemstra »

6.9.2-6 uses 1.6.17 but is not vulnerable. ImageMagick 6.9.2-7 will be using libpng 1.6.19.
.NET + ImageMagick = Magick.NET https://github.com/dlemstra/Magick.NET, @MagickNET, Donate
henry
Posts: 5
Joined: 2015-11-19T14:47:30-07:00
Authentication code: 1151

Re: libpng vulnerability found on Nov 18

Post by henry »

Do you have an estimated time when the imageMagick 6.9.2-7 will be ready?

Thanks a lot
Henry
User avatar
magick
Site Admin
Posts: 11064
Joined: 2003-05-31T11:32:55-07:00

Re: libpng vulnerability found on Nov 18

Post by magick »

ImageMagick 6.9.2-7 will be available 2015-11-28T14:54:58.613Z.
henry
Posts: 5
Joined: 2015-11-19T14:47:30-07:00
Authentication code: 1151

Re: libpng vulnerability found on Nov 18

Post by henry »

I downloaded 6.9.2-8, in the configure, I didn't found anywhere libpng 1.6.19 is specified.
Does it mean imageMagick will use whatever libpng is in the system?
User avatar
magick
Site Admin
Posts: 11064
Joined: 2003-05-31T11:32:55-07:00

Re: libpng vulnerability found on Nov 18

Post by magick »

That's correct. Check the news, ImageMagick is not vulnerable to the PNG exploit.
Post Reply