CVE-2016-5118
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Affected (24)
Products: Graphicsmagick: Graphicsmagick · Suse: Linux Enterprise Debuginfo, Linux Enterprise Software Development Kit, Studio Onsite, Linux Enterprise Desktop, Linux Enterprise Server, Linux Enterprise Workstation Extension · Oracle: Solaris, Linux · +4 more
Show all products
Graphicsmagick: Graphicsmagick · Suse: Linux Enterprise Debuginfo, Linux Enterprise Software Development Kit, Studio Onsite, Linux Enterprise Desktop, Linux Enterprise Server, Linux Enterprise Workstation Extension · Oracle: Solaris, Linux · Opensuse: Leap, Opensuse · Canonical: Ubuntu Linux · Debian: Debian Linux · Imagemagick: Imagemagick
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.23 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 sp4 | |
| Version 11 sp4 | |
| Version 1.3 |
Configuration E
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.04 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0 sp1 | |
| Version 12.0 sp1 | |
| Version 12.0 sp1 | |
| Version 12 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.0.1-7 |
References (44)
Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListRelease Notes
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Broken LinkThird Party AdvisoryVDB Entry
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.397749
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.397749
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.