cbcvebase.
CVE-2016-5118
published 2016-06-10

CVE-2016-5118: The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiangraphicsmagick< graphicsmagick 1.3.24-1 (bookworm)graphicsmagick 1.3.24-1 (bookworm)
debianimagemagick< graphicsmagick 1.3.24-1 (bookworm)graphicsmagick 1.3.24-1 (bookworm)
graphicsmagickgraphicsmagick<= 1.3.23
graphicsmagickgraphicsmagick>= 0 < 1.3.24-11.3.24-1
graphicsmagickgraphicsmagick>= 0 < 1.3.24-11.3.24-1
graphicsmagickgraphicsmagick>= 0 < 1.3.24-11.3.24-1
graphicsmagickgraphicsmagick>= 0 < 1.3.24-11.3.24-1
imagemagickimagemagick< 7.0.1-77.0.1-7
imagemagickimagemagick>= 0 < 8:6.8.9.9-7.18:6.8.9.9-7.1
imagemagickimagemagick>= 0 < 8:6.8.9.9-7.18:6.8.9.9-7.1
imagemagickimagemagick>= 0 < 8:6.8.9.9-7.18:6.8.9.9-7.1
imagemagickimagemagick>= 0 < 8:6.8.9.9-7.18:6.8.9.9-7.1
imagemagickimagemagick>= 0 < 8:6.7.7.10-6ubuntu3.18:6.7.7.10-6ubuntu3.1
imagemagickimagemagick>= 0 < 8:6.8.9.9-7ubuntu5.18:6.8.9.9-7ubuntu5.1
opensuseleap
opensuseopensuse
oraclelinux
oraclelinux
oraclesolaris
oraclesolaris

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL