cbcvebase.
CVE-2005-4601
published 2005-12-31

CVE-2005-4601: The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by…

PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.69%
88.5th percentile
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiangraphicsmagick< graphicsmagick 1.1.7-1 (bookworm)graphicsmagick 1.1.7-1 (bookworm)
debianimagemagick< graphicsmagick 1.1.7-1 (bookworm)graphicsmagick 1.1.7-1 (bookworm)
graphicsmagickgraphicsmagick>= 0 < 1.1.7-11.1.7-1
graphicsmagickgraphicsmagick>= 0 < 1.1.7-11.1.7-1
graphicsmagickgraphicsmagick>= 0 < 1.1.7-11.1.7-1
graphicsmagickgraphicsmagick>= 0 < 1.1.7-11.1.7-1
imagemagickimagemagick
imagemagickimagemagick>= 0 < 6:6.2.4.5-0.66:6.2.4.5-0.6
imagemagickimagemagick>= 0 < 6:6.2.4.5-0.66:6.2.4.5-0.6
imagemagickimagemagick>= 0 < 6:6.2.4.5-0.66:6.2.4.5-0.6
imagemagickimagemagick>= 0 < 6:6.2.4.5-0.66:6.2.4.5-0.6

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.