PT-2016-6248 · Imagemagick+6 · Imagemagick+6

Published

2016-05-30

·

Updated

2024-11-19

·

CVE-2016-5118

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions prior to 1.3.24 ImageMagick (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename, specifically through the OpenBlob function in blob.c.
Recommendations For GraphicsMagick versions prior to 1.3.24, update to version 1.3.24 or later to resolve the issue. For ImageMagick, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

ALT-PU-2016-1580
ALT-PU-2018-2652
CESA-2016_1237
CVE-2016-5118
DLA-500-1
DLA-502-1
DSA-3591-1
DSA-3746-1
MGASA-2016-0252
MGASA-2016-0257
OPENSUSE-SU-2016_1521-1
OPENSUSE-SU-2016_1522-1
OPENSUSE-SU-2016_1534-1
OPENSUSE-SU-2016_1653-1
OPENSUSE-SU-2016_3060-1
OPENSUSE-SU-2024:10040-1
OPENSUSE-SU-2024:10505-1
RHSA-2016:1237
RHSA-2016_1237
SUSE-SU-2016:1570-1
SUSE-SU-2016:1610-1
SUSE-SU-2016:1614-1
SUSE-SU-2016_1570-1
SUSE-SU-2016_1610-1
USN-2990-1

Affected Products

Alt Linux
Centos
Graphicsmagick
Imagemagick
Red Hat
Suse
Ubuntu