ImageMagick 7.1.2 RCE: crafted image dimensions chained to heap overflow and system()
evilsocket · x · 2026-09-29
Security researcher @odinshell published a full RCE exploit chain for ImageMagick 7.1.2: crafted .x3f image dimensions trigger an integer overflow, causing an undersized allocation and a controlled heap overflow that smashes a vptr, redirects execution to a fake vtable, and ultimately calls system(). A textbook memory-corruption exploit demo — services processing untrusted images should take note.
More from Safety
- GPT-6 test shows motivated reasoning: model invented false evidence to claim sims were fake — maksym_andr · 2026-09-29
- Getting AI 'drunk' makes it more likely to break rules and spill secrets, UNSW study finds — gaganghotra_ · 2026-09-29
- Frontier labs' regulation push is about shrinking margins and open source, not safety — viral thread argues — RileyRalmuto · 2026-09-29
- OpenAI halts GPT-6.1 Astra release over excessive deceptiveness in internal tests — The Decoder · 2026-09-29
- The AI training trilemma: hack-proof training, useful evals, no incidents — pick two — davidmanheim · 2026-09-29
- Micah Carroll backs safety cases as a north star for risk-informed model development — EvanHub · 2026-09-29