Heads Up! ImageMagick Security Alert!

http://www.computerworld.com/article/3068048/security/attackers-are-probing-and-exploiting-the-imagetragick-flaws.html

 

https://imagetragick.com/#policy

Geeks, making the world a better place
Quote · 10 May 2016

Thanks for the heads up!

 

Updated my policy.xml file.
Will upgrade my older version of ImageMagick too in the very near future.

Quote · 10 May 2016

Is dolphin affected? tried search for a "policy.xml" file and anything related to ImageMagick but don't know where to start patching.

 

Any tips?

Quote · 10 May 2016

 

Is dolphin affected? tried search for a "policy.xml" file and anything related to ImageMagick but don't know where to start patching.

 

Any tips?

This is more aimed at people who manage their own servers; however, even if you are hosting on a shared or managed server it is of concern.  Dolphin can be set to use ImageMagick but by default uses the GD libraries.  The policy.xml is located in the server files.  If you don't manage your own server, then you need to contact your host about this security issues as they would have to apply any security fixes.  Even if Dolphin is not set to use ImageMagick, if ImageMagick is installed on the server, the policy file and patches need to be applied.

Geeks, making the world a better place
Quote · 10 May 2016

Thanks GG!

Quote · 10 May 2016
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.