PaulB
Well-known member
ImageMagick just released a patch for a serious information disclosure vulnerability. I haven't tested whether this affects XenForo, but it probably does. You should disable ImageMagick and use GD instead, if possible; ImageMagick is prone to serious vulnerabilities. If that isn't an option, check whether your distro has released updated packages for ImageMagick that patch CVE-2022-44268.
Details: https://www.metabaseq.com/imagemagick-zero-days/#:~:text=CVE-2022-44268: Arbitrary Remote Leak
As of writing:
Details: https://www.metabaseq.com/imagemagick-zero-days/#:~:text=CVE-2022-44268: Arbitrary Remote Leak
As of writing:
- Debian has released a patch for bullseye, but not for any other versions: https://security-tracker.debian.org/tracker/CVE-2022-44268
- Ubuntu has released a patch for bionic (18.04.6 LTS), but not for any other versions: https://ubuntu.com/security/CVE-2022-44268
Last edited: