gwu-libraries / scholarspace

GWU's Sufia-based repository app for preservation and open access to scholarly output of the GWU community
MIT License
0 stars 0 forks source link

Update ImageMagick policy to prevent remote code execution #209

Closed kerchner closed 8 years ago

kerchner commented 8 years ago

A vulnerability in ImageMagick was discovered and publicized on 3-May-2016. Issue and recommended solution are described here: https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588 (also see https://imagetragick.com/ )

Create a policy.xml file in the repo here containing the additional policy configurations, and add a step to the README to replace the default policy.xml file that deploys with the default ImageMagick install.