MantisBT - MEGA
View Issue Details
0000147MEGA[All Projects] Feedbackpublic2016-05-05 10:312016-05-06 07:46
guest 
gstecher 
normalminorhave not tried
resolvedno change required 
MEGA-CC 11 (command line version) 
 
Joshua
Jarrell
Joshua.Jarrell@fsis.usda.gov
Joshua.Jarrell@fsis.usda.gov
0000147: Vulnerability in Image Magick released
Dear help desk,

  We had a question as to what the impact is of having Image Magick 6.8 installed on Mega 6. Can Image Magick be upgraded independently or would it require an upgrade to Mega 7 (assuming that this version has been upgraded past versions 7.0.1-1 and 6.9.3-10).
https://www.us-cert.gov/ncas/current-activity/2016/05/04/ImageMagick-Vulnerability [^]
  I can be contacted via the attached e-mail or by phone (202) 708-8755.

V/r,
  Josh Jarrell
No tags attached.
Issue History
2016-05-05 10:31guestNew Issue
2016-05-06 07:46gstecherNote Added: 0003661
2016-05-06 07:46gstecherStatusnew => resolved
2016-05-06 07:46gstecherResolutionopen => no change required
2016-05-06 07:46gstecherAssigned To => gstecher

Notes
(0003661)
gstecher   
2016-05-06 07:46   
Hi Joshua,

I am writing in response to your question regarding the MEGA software and ImageMagick. MEGA6 does not install ImageMagick nor does it use ImageMagick that is installed on user's systems but rather MEGA6 is packaged with the ImageMagick libraries that it uses. MEGA6 also does not accept images as user input for processing so the recently reported vulnerability is in theory, not applicable. Upgrading ImageMagick on your system will not affect MEGA6 adversely. However, because some ImageMagick libraries are packaged with MEGA6, installing the newest version of ImageMagick will not remove those libraries. For peace of mind however, you can do the following:

    Uninstall MEGA6 (this will remove the ImageMagick libraries packaged with MEGA6)
    Install MEGA7 (starting with version 7, MEGA no longer uses ImageMagick)

--
Best regards,

Glen Stecher
Institute for Genomics and Evolutionary Medicine
igem.temple.edu