Why Nostr? What is Njump?
2024-07-03 12:16:27
in reply to

Bill Mill on Nostr: The vector for us was that somebody uploaded a file with a jpg extension that was ...

The vector for us was that somebody uploaded a file with a jpg extension that was actually an EPS (postscript) file. A javascript library passed the image to imagemagick, which detected it as a postscript file and passed it off to ghostscript (we had no idea it would do this), which then happily gave shell to the attacker. madness
Author Public Key
npub1qwsjwlykppfdqcvujrnce6yr7je5vcgjltg2umywykr0sm0k06zs8t96m8