The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imagemagick | Imagemagick | 6.2.4.5 (including) | 6.2.4.5 (including) |
Red Hat Enterprise Linux 3 | RedHat | ImageMagick-0:5.5.6-18 | * |
Red Hat Enterprise Linux 4 | RedHat | ImageMagick-0:6.0.7.1-14 | * |
Graphicsmagick | Ubuntu | devel | * |
Graphicsmagick | Ubuntu | edgy | * |
Graphicsmagick | Ubuntu | feisty | * |
Imagemagick | Ubuntu | dapper | * |
Imagemagick | Ubuntu | devel | * |
Imagemagick | Ubuntu | edgy | * |
Imagemagick | Ubuntu | feisty | * |