Remote code execution vulnerability in libmagickwand?
Remote code execution vulnerability in libmagickwand?
Sorry if this question has already been answered somewhere but my searches have come up empty. We package VIPS with libmagickwand-dev Depends: libmagickwand5 (= 8:6.7.7.10-6ubuntu3), libmagickcore5-extra (= 8:6.7.7.10-6ubuntu3), libmagickcore-dev (= 8:6.7.7.10-6ubuntu3). Could the https://imagetragick.com vulnerability be exposed?
Re: Remote code execution vulnerability in libmagickwand?
See https://www.imagemagick.org/discourse-s ... =4&t=29588. Add the suggested policies and you should be safe.