Severity
9.8CRITICAL
EPSS
31.8%
top 3.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateMay 13

Description

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages14 packages

Debianimagemagick< 8:6.8.9.9-7.1+3
Debiangraphicsmagick< 1.3.24-1+3
NVDoracle/linux6, 7+1

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

4
GHSA
GHSA-6w95-mr48-gp8c: The OpenBlob function in blob2022-05-13
OSV
CVE-2016-5118: The OpenBlob function in blob2016-06-10
CVEList
CVE-2016-5118: The OpenBlob function in blob2016-06-10
OSV
imagemagick vulnerabilities2016-06-02

🔍Detection Rules

4
Suricata
ET WEB_SERVER Possible CVE-2016-5118 Exploit SVG attempt M22016-06-01
Suricata
ET WEB_SERVER Possible CVE-2016-5118 Exploit MVG attempt M12016-06-01
Suricata
ET WEB_SERVER Possible CVE-2016-5118 Exploit SVG attempt M12016-06-01
Suricata
ET WEB_SERVER Possible CVE-2016-5118 Exploit MVG attempt M22016-06-01

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2016-06-02
Red Hat
ImageMagick: Remote code execution via filename2016-05-29
Debian
CVE-2016-5118: graphicsmagick - The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick ...2016

💬Community

4
Bugzilla
CVE-2016-5118 graphicsmagick: ImageMagick: Remote code execution via filename [fedora-all]2016-05-30
Bugzilla
CVE-2016-5118 graphicsmagick: ImageMagick: Remote code execution via filename [epel-all]2016-05-30
Bugzilla
CVE-2016-5118 ImageMagick: Remote code execution via filename [fedora-all]2016-05-30
Bugzilla
CVE-2016-5118 ImageMagick: Remote code execution via filename2016-05-30