Home Guides Glossary

Protect Your Server from ImageMagick Vulnerability

A security vulnerability in ImageMagick was announced on May 4th, 2016. If your Linux server uses ImageMagick to handle image uploads, you should make changes to your server immediately to protect it from a possible compromise.

Am I affected?

Not all hosting products are affected by the ImageMagick vulnerability.

Hosting Type Affected?
Shared Hosting (cPanel, Managed WordPress, Plesk) No
VPS or Dedicated Server with cPanel No
VPS or Dedicated server without cPanel Yes
Cloud Server Yes

If you turned automatic updates off on your cPanel server, you may still be vulnerable.

Protect your server

To protect your server from the ImageMagick vulnerability, you need to make changes to your policy.xml file for ImageMagick.

  1. Connect to your server with SSH.
  2. Locate your policy.xml file for ImageMagick. The path to this file may be different depending on your Linux version.
    Linux Versions Path
    Ubuntu
    Debian 7
    CentOS
    RHEL
    Arch Linux
    /etc/ImageMagick/policy.xml
    Debian 8
    Fedora
    /etc/ImageMagick-6/policy.xml
    FreeBSD /usr/local/etc/ImageMagick-6/policy.xml
    CentOS 6 with cPanel/WHM /usr/local/cpanel/3rdparty/etc/ImageMagick-6/policy.xml
  3. Open this policy.xml file in a text editor:
    sudo vim /etc/ImageMagick/policy.xml
  4. Add the following lines to the <policymap> section of the file:
    <policy domain="coder" rights="none" pattern="EPHEMERAL" />
    <policy domain="coder" rights="none" pattern="URL" />
    <policy domain="coder" rights="none" pattern="HTTPS" />
    <policy domain="coder" rights="none" pattern="MVG" />
    <policy domain="coder" rights="none" pattern="MSL" />
    <policy domain="coder" rights="none" pattern="TEXT" />
    <policy domain="coder" rights="none" pattern="SHOW" />
    <policy domain="coder" rights="none" pattern="WIN" />
    <policy domain="coder" rights="none" pattern="PLT" />
  5. Save and close the file:
    :wq!

Once these changes have been made, your server will be protected from the ImageMagick vulnerability.

Domain Registration

Pay less for website domain names. Register your own .com, .net or .org for as low as $10.18 per year. We have everything you need to get online with your new domain.

Website Builder

For as little as $3.89 per month you can build your Website online with Website Builder using our easy to use professional templates. Play Video - Demo

Quick Shopping Cart

Build and run your own successful online store in minutes. You're just five easy steps away! Shopping Cart works with Google® and eBay® Play Video

Website Hosting

Everything needed to give your website the high-performance home it deserves.  Protect transactions and secure your customer's data with a SSL Certificate

Copyright © 2005 - 2017. All rights reserved. Privacy Policy