Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does not check for ImageMagick CVE-2016-3714 mitigation #5

Open
rsiddall opened this issue Sep 6, 2017 · 0 comments
Open

Does not check for ImageMagick CVE-2016-3714 mitigation #5

rsiddall opened this issue Sep 6, 2017 · 0 comments

Comments

@rsiddall
Copy link
Owner

rsiddall commented Sep 6, 2017

The BBB 1.0 install instructions say at http://docs.bigbluebutton.org/10install.html#imagemagick-security-issues that the version of ImageMagick for Ubuntu 14.04 is vulnerable to CVE-2016-3714 (https://imagetragick.com/). Mitigation appears to be ensuring that all of the specified lines like "<policy domain="coder" rights="none" pattern="EPHEMERAL" />" appear in the <policymap> section of /etc/ImageMagick/policy.xml. The bbb-install script does not do this yet.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant