CVE Vulnerabilities

CVE-2016-5118

Published: Jun 10, 2016 | Modified: Aug 01, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

Affected Software

Name Vendor Start Version End Version
Graphicsmagick Graphicsmagick * 1.3.23 (including)
Graphicsmagick Ubuntu artful *
Graphicsmagick Ubuntu precise *
Graphicsmagick Ubuntu trusty *
Graphicsmagick Ubuntu wily *
Graphicsmagick Ubuntu xenial *
Graphicsmagick Ubuntu yakkety *
Graphicsmagick Ubuntu zesty *
Imagemagick Ubuntu artful *
Imagemagick Ubuntu bionic *
Imagemagick Ubuntu cosmic *
Imagemagick Ubuntu devel *
Imagemagick Ubuntu precise *
Imagemagick Ubuntu trusty *
Imagemagick Ubuntu wily *
Imagemagick Ubuntu xenial *
Imagemagick Ubuntu yakkety *
Imagemagick Ubuntu zesty *
Red Hat Enterprise Linux 6 RedHat ImageMagick-0:6.7.2.7-5.el6_8 *
Red Hat Enterprise Linux 7 RedHat ImageMagick-0:6.7.8.9-15.el7_2 *

References