10

CVE-2016-5118

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

Data is provided by the National Vulnerability Database (NVD)
GraphicsmagickGraphicsmagick Version <= 1.3.23
SuseLinux Enterprise Debuginfo Version11 Updatesp4
SuseStudio Onsite Version1.3
OracleSolaris Version10
OracleSolaris Version11.3
OracleLinux Version6
OracleLinux Version7
OpensuseLeap Version42.1
OpensuseOpensuse Version13.2
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version15.10
CanonicalUbuntu Linux Version16.04 SwEditionlts
DebianDebian Linux Version8.0
SuseLinux Enterprise Desktop Version12 Update-
SuseLinux Enterprise Desktop Version12.0 Updatesp1
SuseLinux Enterprise Server Version12 Update-
SuseLinux Enterprise Server Version12.0 Updatesp1
ImagemagickImagemagick Version < 7.0.1-7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 35.42% 0.969
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
http://www.securityfocus.com/bid/90938
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1035984
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1035985
Third Party Advisory
Broken Link
VDB Entry