Skip to content

diaspora* 0.7.18.2

Latest
Compare
Choose a tag to compare
@denschub denschub released this 10 Jul 00:00
· 787 commits to develop since this release
v0.7.18.2
f042f5d

This release addresses possible security issues when processing images uploaded by users that is affecting some system configurations.

This fix was heavily inspired by Mastodon's fix for GHSA-9928-3cp5-93fm, and while diaspora*s attack surface is significantly smaller and some operating systems do ship a restrictive ImageMagick policy, this release makes sure that everyone is safe.

Thank you Cure53 for finding this issue, thank you Mozilla for paying Cure53 to look into it, and thanks for Mastodon for fixing it.