Closed
Bug 1269588
Opened 10 years ago
Closed 10 years ago
Imagemagick 0day: Is it used anywhere?
Categories
(Core :: Graphics: ImageLib, defect)
Core
Graphics: ImageLib
Tracking
()
RESOLVED
INVALID
People
(Reporter: abillings, Unassigned)
Details
Apparently there is a 0day out in the wild for imagemagick. I don't think we use it anywhere but I thought it would be good to ask. Does anyone know for sure?
| Reporter | ||
Comment 1•10 years ago
|
||
Cc'ing a bunch of people. I don't think we use this anywhere in platform or Firefox but want to be sure.
Component: Graphics → ImageLib
Comment 2•10 years ago
|
||
We may use it on servers, but neither DXR or MXR finds any 'magick code files in our tree.
Updated•10 years ago
|
Flags: needinfo?(milan)
Comment 3•10 years ago
|
||
I don't think we use imagemagick anywhere in Firefox, but I'm guessing that imagemagick pulls in various external libraries to decode/encode images. So if the 0day is in one of those libraries, and we use the same library we could be affected. So we'd need more info on the 0day I would guess.
Comment 4•10 years ago
|
||
Nothing to add here, I'm with Timothy on this one. Maybe Jeff has a different view.
Flags: needinfo?(milan) → needinfo?(jmuizelaar)
| Reporter | ||
Comment 5•10 years ago
|
||
Details of issue (as much as anything):
https://imagetragick.com/
Comment 6•10 years ago
|
||
We don't use any imagemagick code.
Status: NEW → RESOLVED
Closed: 10 years ago
Flags: needinfo?(jmuizelaar)
Resolution: --- → INVALID
Updated•10 years ago
|
Group: gfx-core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•