MantisBT - MEGA
View Issue Details
0000146MEGA[All Projects] Feedbackpublic2016-05-05 10:282016-05-06 07:31
guest 
gstecher 
normalminorhave not tried
resolvedno change required 
MEGA 11 (Graphical Interface version) 
 
Frank
Niagro
frank.niagro@fsis.usda.gov
frank.niagro@fsis.usda.gov
0000146: ImageMajik Security Vulnerability
US-CERT has reported that there is a security vulnerability in ImageMajik (Vulnerability Note VU#250519 ImageMagick does not properly validate input before processing images using a delegate). The recommended remediation is to install ImageMajik version 7.0.1-1. Will installation of the newer version of ImageMajik adversely affect MEGA6? Alternatively, if we upgrade to MEGA7 will that also resolve the issue?
No tags attached.
Issue History
2016-05-05 10:28guestNew Issue
2016-05-06 07:31gstecherNote Added: 0003660
2016-05-06 07:31gstecherStatusnew => resolved
2016-05-06 07:31gstecherResolutionopen => no change required
2016-05-06 07:31gstecherAssigned To => gstecher

Notes
(0000038)
Nikita Vikhrev   
1969-12-31 17:33   
I could not reproduce it in MY latest version. I might have fixed it sometime ago.
(0000040)
gstecher   
1969-12-31 17:33   
I am unable to reproduce this error using the latest code recieved 12-01-03. I am going to close out the bug.

edited on: 12-01 14:13
(0003660)
gstecher   
2016-05-06 07:31   
Hi Frank,

I am writing in response to your question regarding the MEGA software. Installing the newest version of ImageMagick should not affect MEGA6. However, a better solution may be to first, uninstall MEGA6, and then install MEGA7 which does not use ImageMagick at all.

--
Best regards,

Glen Stecher
Institute for Genomics and Evolutionary Medicine
igem.temple.edu