web hosting line
1.866.605.2484

Web hosting

Go Back   Web Hosting Forum - Web hosting discussion at SiteGround.com > Popular Software > Other Software and Applications

Reply
 
Thread Tools Display Modes
  #1  
Old 08-16-2006, 10:14 PM
RedKarl RedKarl is offline
Junior Member
 
Join Date: Aug 2006
Posts: 19
Default Comprimised version of ImageMagick

Hi siteguys,
When I go to install and congfigure ImageMagick in Gallery I get the following securint warning:
Warning: This version of ImageMagick has a known vulnerability that can be exploited to cause infinite loops. You may wish to upgrade. This determination may be inaccurate for Debian.

When I click on the link in the message: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2005-1739
I am told that all versions up to 6.2.2 are vulnerable to the security flaw. I am also told in Gallery that you have version 6.0.7 installed.

Are there plans to upgrage the version you have installed?

Thanks for your great work by the way.
Reply With Quote
  #2  
Old 08-17-2006, 04:52 AM
Cinder Cinder is offline
SiteGround Team Member
 
Join Date: Jul 2006
Posts: 7
Default

Hello,

We have installed the latest version of ImageMagic on the server hosting your account, which should resolve the problem with the error message that you are currently receiving.

root@sg5:~/ImageMagick-6.2.9#/usr/bin/convert -v
Version: ImageMagick 6.2.9 08/17/06 Q16 http://www.imagemagick.org
Copyright: Copyright (C) 1999-2006 ImageMagick Studio LLC
__________________
John
SiteGround Admin Dept.
www.SiteGround.com

Last edited by Kate; 06-25-2007 at 08:47 AM.
Reply With Quote
  #3  
Old 08-17-2006, 06:51 PM
RedKarl RedKarl is offline
Junior Member
 
Join Date: Aug 2006
Posts: 19
Default

Hi John,
Thanks for the prompt reply but when I tried it again this morning I get the same message in Gallery. It seems that you still have the comprimised version: 6.0.7 installed on my server. By the way, how do you know what server is hosting my account? I never gave you those details and my login to this board doesn't include them anywhere. You must have gnosis! :-)
Reply With Quote
  #4  
Old 08-18-2006, 04:20 AM
Cinder Cinder is offline
SiteGround Team Member
 
Join Date: Jul 2006
Posts: 7
Default

Hello,

Well it wasn't easy but I think we've managed to locate your account by investigating your previous posts I will not say which one it is since you haven't done so yourself so far.

Anyways, I will assume that your account is hosted on the siteground5.com server (unless you have more than one account with us), which has the latest version of ImageMagic available:

root@sg5:~# /usr/bin/convert
Version: ImageMagick 6.2.9 08/17/06 Q16 http://www.imagemagick.org
Copyright: Copyright (C) 1999-2006 ImageMagick Studio LLC

If we are mistaken, please state which your account is, or on which it is hosted on.
__________________
John
SiteGround Admin Dept.
www.SiteGround.com
Reply With Quote
  #5  
Old 08-18-2006, 07:10 PM
RedKarl RedKarl is offline
Junior Member
 
Join Date: Aug 2006
Posts: 19
Default

Thanks for your reply again John, my installation of Gallery is still reporting the old comprimised version.

The server ip address is 67.15.250.7 (from my control panel), the site name is supashotz.com.

Thanks again for your work.
Reply With Quote
  #6  
Old 08-20-2006, 12:16 AM
rodpacker rodpacker is offline
Junior Member
 
Join Date: Jul 2006
Posts: 27
Default Hey mate....

I've had a different problem, probably caused by the same fact, which is that some ISP's have an internal cache to save traffic (which is I think pretty weird).
However result of this is, that you will still get the old data (your error message) for a few days even though you deleted your local cache (have you done that yet?)
Easiest way to make sure this isn't your problem, is to go to somebody else's computer and try it from there (if it is a friend, ask what webprovider he is going through to make sure he isn't using the same ISP as u are )
cheers
rodpacker
Reply With Quote
  #7  
Old 08-20-2006, 06:51 PM
RedKarl RedKarl is offline
Junior Member
 
Join Date: Aug 2006
Posts: 19
Default

Yes, good point rodpacker. Just a question first to the Siteground people: now I have given you my domain details, have you checked that the software has indeed been updated on that server? Thanks again.
-Karl-
Reply With Quote
  #8  
Old 08-21-2006, 08:39 AM
RedKarl RedKarl is offline
Junior Member
 
Join Date: Aug 2006
Posts: 19
Default

siteground support, the Directory I'm using to point to ImageMagick/GraphicsMagick binaries is /usr/bin/ is that the correct directory I should be using? It is still saying that it has the comprimised version: 6.0.7
Reply With Quote
  #9  
Old 08-21-2006, 06:14 PM
RedKarl RedKarl is offline
Junior Member
 
Join Date: Aug 2006
Posts: 19
Unhappy

Does anybody else using siteground for shared hosting Gallery2 have this issue? Or is it only me?
Reply With Quote
  #10  
Old 08-22-2006, 05:54 AM
Cinder Cinder is offline
SiteGround Team Member
 
Join Date: Jul 2006
Posts: 7
Default

Hello,

We have upgraded the ImageMagick tool on the server hosting your supashotz.com

/usr/bin/convert
Version: ImageMagick 6.2.9 08/22/06 Q16 http://www.imagemagick.org
Copyright: Copyright (C) 1999-2006 ImageMagick Studio LLC

The prefix you should be using when installing the Gallery script is /usr/bin/ as you have been using so far.

You should now be able to install Gallery without any futrher troubles.
__________________
John
SiteGround Admin Dept.
www.SiteGround.com
Reply With Quote
  #11  
Old 08-22-2006, 08:02 AM
RedKarl RedKarl is offline
Junior Member
 
Join Date: Aug 2006
Posts: 19
Talking Thank you!

Ahaaaaa! Thank you for your help. I have installed Imagemagick at last.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 06:21 PM.

Copyright © SiteGround.com Inc