https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=imagemagick
There have been a number of zero days.
My entire interaction with Imagemagick has been removing it. Often with great difficulty because there is some odd dependency.
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=imagemagick
There have been a number of zero days.
My entire interaction with Imagemagick has been removing it. Often with great difficulty because there is some odd dependency.
[1] Random search result that appears to corroborate my claim: https://blog.aquasec.com/container-isolation
If the security folks at your job truly doesn't consider containers security boundaries then they are wrong. What seems more likely is they don't consider containers alone a _good enough_ security boundary. And that's fine, some places consider separate processes with different rights good enough security boundaries. Others consider two boxes that are able to interact with each other not a good enough security boundary. It doesn't change that things that weren't secure enough for the use case are still security boundaries.
So you could use it in some typical dev workflows (or other business workflows) that are purely internal and maybe in certain non-internal processes where the inputs are strictly limited to trusted ones. But not, e.g., in services/apps that could process untrusted inputs.
(Seems like there are a number of leaks too, but since it's process-oriented, those probably won't be that hard to live with. They might be hard to notice normally.)
?
Same. I've successfully moved all my image manipulation requirements to libVIPS. Far more performant and with a ton less memory usage.