2
2

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 5 years have passed since last update.

極力yumでCentOS6でImageMagickの脆弱性対応

Posted at

必要であればリポジトリ追加
rpm -ivh epel-release-6-8.noarch.rpm rpm -ivh remi-release-6.rpm

まず削除する
yum remove -y ImageMagick
必要な物を入れる
yum install -y http://pkgrepo.linuxtech.net/el6/release/x86_64/liblcms2-2.4-1.el6.x86_64.rpm yum install -y --enablerepo=epel yum install libwebp
新しいImageMagickを入れる
yum install -y --enablerepo=remi ImageMagick-last
テストツールを入れる
cd /usr/local/src/ git clone https://github.com/ImageTragick/PoCs.git cd PoCs
テストツール実行
./test.sh

UNSAFEが無ければOK。
UNSAFEあったら
vi /etc/ImageMagick-last/ImageMagick-6/policy.xml
下記を追加
<policy domain="coder" rights="none" pattern="EPHEMERAL" /> <policy domain="coder" rights="none" pattern="URL" /> <policy domain="coder" rights="none" pattern="HTTPS" /> <policy domain="coder" rights="none" pattern="MVG" /> <policy domain="coder" rights="none" pattern="MSL" /> <policy domain="coder" rights="none" pattern="TEXT" /> <policy domain="coder" rights="none" pattern="SHOW" /> <policy domain="coder" rights="none" pattern="WIN" /> <policy domain="coder" rights="none" pattern="PLT" />

2
2
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
2
2

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?