You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jul 13, 2023. It is now read-only.
GraphicsMagick is very close to ImageMagick but has a few missing options like 'convert -layers'. It would be nice if GraphicsMagick was also supported somehow.
The text was updated successfully, but these errors were encountered:
During a pentest at my shop, a researcher uploaded a jpg that was crafted to exponentially consume memory. It effectively created a denial of service on the server. It is somehow exploiting a bug in ImageMagick. The exploit triggers when Paperclip calls the identify command from ImageMagick.
I attempted to replicate the issue with GraphicsMagick and it would not reproduce. Consequently, allowing the ability to switch the underlying 'swiss-army-knife' image tool would be very useful. As the code is currently written, we will have to patch all code that references ImageMagick in order to use GraphicsMagick.
GraphicsMagick is very close to ImageMagick but has a few missing options like 'convert -layers'. It would be nice if GraphicsMagick was also supported somehow.
The text was updated successfully, but these errors were encountered: