FAQ › General

What to do when thumbnails of PDF files are not displayed in Redmine

Created on 2022-06-24  •  KUROTANI Akihiro

Since Redmine 4.1, a thumbnail is displayed when you attach a PDF. However, in the default state immediately after the installation of Redmine, the thumbnail is not displayed. This article explains the configuration change that is required to display thumbnails of PDF files.

Conditions for displaying thumbnails

  • "Display attachment thumbnails" in "Administration" → "Settings" → "Display" is turned on.
  • ImageMagick with Ghostscript support is installed on the Redmine server (ImageMagick in most environments supports this).
  • If the OS of the Redmine server is Windows, the Redmine version is 5.0 or later.

Notes

  • In step 2, confirm that the version of Ghostscript is a version in which the vulnerability is fixed, and then perform step 3.

Steps

Step 1: Log in to the server that runs Redmine.

Step 2: Run gs --version to output the version number of Ghostscript.

If the version number is 9.25 or later, the vulnerability is fixed.

$ gs --version
9.55.0

Step 3: Change the following line in /etc/ImageMagick-6/policy.xml.

  • Before the change
<policy domain="coder" rights="none" pattern="PDF" />
  • After the change
<policy domain="coder" rights="read" pattern="PDF" />

Explanation

Since Redmine 4.1, a thumbnail is displayed when you attach a PDF.

PDF thumbnails are generated with the convert command, which is included in the ImageMagick package. The convert command in turn uses the gs command, which is included in the Ghostscript package.

In 2018, a vulnerability was found in the Ghostscript package.

Alert regarding vulnerabilities in the -dSAFER option of Ghostscript (JPCERT/CC)

As a workaround for this vulnerability, the default configuration of the ImageMagick package was changed to disable the processing of PDF files.

As a result, the gs command cannot generate PDF thumbnails unless you change the ImageMagick configuration. The normal installation procedure of Redmine does not change the ImageMagick configuration. For this reason, a Redmine that was installed in the normal way cannot display PDF thumbnails.

After that, version 9.25 of Ghostscript, which fixes the vulnerability, was released.

Artifex Software Version 9.25 (2018-09-13)

To keep the server secure, confirm that the version of Ghostscript is 9.25 or later before you perform the steps above.