TBH, I can't really blame ImageMagick devs too much for this. They're not making an image editing suite for web-facing services with access to sensitive user data. They're making an image editing suite for the Linux command line, which web devs happen to use on user-submitted images with absolutely no sanitization. The latter part of the sentence is the problem.
Adding to that, ImageMagick had it's first release in 1990! That's half a decade before the first release of Apache. It's no surprise some of the code in ImageMagick make it unfit for unfiltered use in web apps, when it was written before graphics-capable webservers, even graphics-capable browsers, were a thing.
What we really need is for someone to write a security-focused universal wrapper, that plugs straight into existing frameworks, so everyone can get the benefit of best-practices, and can report vulns and get them secured quickly.
So really, blaming ImageMagick is not that far from blaming Python for having vulnerabilities if you run a Django app taking unsanitized form input and doing subprocess.Popen() with it.
(That's not to say the "imagetragick" folks are wrong for alerting the community, using that moniker to increase awareness.)
> TBH, I can't really blame ImageMagick devs too much for this. They're not making an image editing suite for web-facing services with access to sensitive user data. They're making an image editing suite for the Linux command line
On the other hand, CLI image display and edition doesn't mean it'll only face trusted content, it's not rare to download a file and display it or further manipulate it.
Adding to that, ImageMagick had it's first release in 1990! That's half a decade before the first release of Apache. It's no surprise some of the code in ImageMagick make it unfit for unfiltered use in web apps, when it was written before graphics-capable webservers, even graphics-capable browsers, were a thing.
What we really need is for someone to write a security-focused universal wrapper, that plugs straight into existing frameworks, so everyone can get the benefit of best-practices, and can report vulns and get them secured quickly.
So really, blaming ImageMagick is not that far from blaming Python for having vulnerabilities if you run a Django app taking unsanitized form input and doing subprocess.Popen() with it.
(That's not to say the "imagetragick" folks are wrong for alerting the community, using that moniker to increase awareness.)