logoalt Hacker News

oefrhatoday at 4:13 AM4 repliesview on HN

Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it's easier than ever to turn vulnerabilities into full compromises. At some point we'll have to replace all parsers with something at least as safe as https://github.com/google/wuffs right? Otherwise ImageMagick and co. will just keep giving.


Replies

oefrhatoday at 4:42 AM

Btw there are so many "critical" vulnerabilities in libheif I can't even tell if I have them all patched. Just awesome.

https://github.com/strukturag/libheif/security/advisories?qu...

https://ubuntu.com/security/notices/USN-8649-1

https://ubuntu.com/security/notices/USN-8683-1

https://ubuntu.com/security/notices/USN-8774-1

show 1 reply
walrus01today at 4:24 AM

It does make me wonder how much this could be hardened by, to put it in an extremely crude way, taking the current imagemagick code base and throwing a bunch of adversarial SOTA LLMs at it to discover 'bugs' and exploits of this nature until it can be coaxed into a less dangerous state. Or even using the LLMs to fully port its functionality to a memory safe language. Would take a while to get all the changes approved and then into various distribution imagemagick packages.

show 1 reply
djxfadetoday at 5:11 AM

PHP still rules the world, even though many doesn't want to realize it. It's still the biggest web language by a far margin

show 1 reply
someothherguyytoday at 6:08 AM

too powerful to give up, sweet imagick love