Re: Exploitable Windows installation Lyx 2.3.3 ImageMagick 7.0.7-27

2019-11-18 Thread Pavel Sanda
On Sat, Nov 16, 2019 at 12:56:51PM +0100, Daniel wrote: > Just because some users might be able to do this doesn't mean that all LyX > users on Windows are able to. Using Linux and, in particular, via the Linux > Subsystem isn't something that comes easy for many Windows users. The Linux >

Re: Exploitable Windows installation Lyx 2.3.3 ImageMagick 7.0.7-27

2019-11-16 Thread Richard Kimberly Heck
On 11/15/19 12:27 PM, Pavel Sanda wrote: > On Fri, Nov 15, 2019 at 10:29:37AM -0500, John wrote: >> Lyx for Windows installer 2.3.3-1 installs ImageMagick 7.0.7-27. This >> version is subject to multiple buffer overflows (stack and heap) and >> several other vulnerabilities, allowing remote code

Re: Exploitable Windows installation Lyx 2.3.3 ImageMagick 7.0.7-27

2019-11-16 Thread Richard Kimberly Heck
On 11/16/19 6:56 AM, Daniel wrote: > On 15/11/19 18:27, Pavel Sanda wrote: >> On Fri, Nov 15, 2019 at 10:29:37AM -0500, John wrote: >>> Lyx for Windows installer 2.3.3-1 installs ImageMagick 7.0.7-27.  This >>> version is subject to multiple buffer overflows (stack and heap) and >>> several other

Re: Exploitable Windows installation Lyx 2.3.3 ImageMagick 7.0.7-27

2019-11-16 Thread Daniel
On 15/11/19 18:27, Pavel Sanda wrote: On Fri, Nov 15, 2019 at 10:29:37AM -0500, John wrote: Lyx for Windows installer 2.3.3-1 installs ImageMagick 7.0.7-27. This version is subject to multiple buffer overflows (stack and heap) and several other vulnerabilities, allowing remote code execution

Re: Exploitable Windows installation Lyx 2.3.3 ImageMagick 7.0.7-27

2019-11-15 Thread Pavel Sanda
On Fri, Nov 15, 2019 at 10:29:37AM -0500, John wrote: > Lyx for Windows installer 2.3.3-1 installs ImageMagick 7.0.7-27. This > version is subject to multiple buffer overflows (stack and heap) and > several other vulnerabilities, allowing remote code execution if the user > opens a LyX document

Exploitable Windows installation Lyx 2.3.3 ImageMagick 7.0.7-27

2019-11-15 Thread John
Lyx for Windows installer 2.3.3-1 installs ImageMagick 7.0.7-27. This version is subject to multiple buffer overflows (stack and heap) and several other vulnerabilities, allowing remote code execution if the user opens a LyX document incorporating a specially-crafted image. Solution: Upgrade to