CVE-2016-5239Improper Access Control in Graphicsmagick

Severity
9.8CRITICALNVD
EPSS
0.9%
top 24.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 14

Description

The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

debiandebian/imagemagick< graphicsmagick 1.3.24-1 (bookworm)
debiandebian/graphicsmagick< graphicsmagick 1.3.24-1 (bookworm)
Debianimagemagick/imagemagick< 8:6.9.6.2+dfsg-2+3
Debiangraphicsmagick/graphicsmagick< 1.3.24-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v696-qhvw-8g5m: The gnuplot delegate functionality in ImageMagick before 62022-05-14
OSV
CVE-2016-5239: The gnuplot delegate functionality in ImageMagick before 62017-03-15

📋Vendor Advisories

2
Red Hat
ImageMagick,GraphicsMagick: Gnuplot delegate vulnerability allowing command injection2016-05-08
Debian
CVE-2016-5239: graphicsmagick - The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMag...2016

💬Community

1
Bugzilla
CVE-2016-5239 ImageMagick,GraphicsMagick: Gnuplot delegate vulnerability allowing command injection2016-05-09