Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5118

Опубликовано: 29 мая 2016
Источник: redhat
CVSS2: 6.8
EPSS Средний

Описание

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

It was discovered that ImageMagick did not properly sanitize certain input before using it to invoke processes. A remote attacker could create a specially crafted image that, when processed by an application using ImageMagick or an unsuspecting user using the ImageMagick utilities, would lead to arbitrary execution of shell commands with the privileges of the user running the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ImageMagickAffected
Red Hat OpenShift Enterprise 2ImageMagickAffected
Red Hat Enterprise Linux 6ImageMagickFixedRHSA-2016:123716.06.2016
Red Hat Enterprise Linux 7ImageMagickFixedRHSA-2016:123716.06.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1340814ImageMagick: Remote code execution via filename

EPSS

Процентиль: 97%
0.35422
Средний

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

CVSS3: 9.8
nvd
около 9 лет назад

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

CVSS3: 9.8
debian
около 9 лет назад

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and Im ...

suse-cvrf
около 9 лет назад

Security update for ImageMagick

suse-cvrf
около 9 лет назад

Security update for GraphicsMagick

EPSS

Процентиль: 97%
0.35422
Средний

6.8 Medium

CVSS2