"The exploit is trivial, so we expect it to be available within hours of this post," Huber wrote in a blog post published Tuesday. He went on to say: "We have collectively determined that these vulnerabilities are available to individuals other than the person(s) who discovered them. An unknowable number of people having access to these vulnerabilities makes this a critical issue for everyone using this software."
Et:
The code-execution bug was discovered by security researcher Nikolay Ermishkin, who is expected to release an advisory in the coming hours. Huber went public in an attempt to prevent malicious attacks after learning the vulnerability details were already being widely disseminated ahead of Ermishkin's planned disclosure. The code-execution vulnerability came to light after it was used in recent bug bounty submissions.
Depending on the time of day, the French go either way.
[^] # Re: Déjà exploité ?
Posté par Frank-N-Furter . En réponse au journal Faille dans ImageMagick. Évalué à 2.
L'article d'Ars:
Et:
Depending on the time of day, the French go either way.