Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6w95-mr48-gp8c

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

EPSS

Процентиль: 97%
0.35422
Средний

9.8 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

redhat
больше 9 лет назад

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

CVSS3: 9.8
nvd
около 9 лет назад

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

CVSS3: 9.8
debian
около 9 лет назад

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and Im ...

suse-cvrf
около 9 лет назад

Security update for ImageMagick

EPSS

Процентиль: 97%
0.35422
Средний

9.8 Critical

CVSS3

Дефекты

CWE-284