CVE-2016-5118
10.06.2016, 15:59
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.Enginsight
| Vendor | Product | Version |
|---|---|---|
| graphicsmagick | graphicsmagick | 𝑥 ≤ 1.3.23 |
| suse | studio_onsite | 1.3 |
| oracle | solaris | 11.3 |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.2 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
| canonical | ubuntu_linux | 16.04 |
| debian | debian_linux | 8.0 |
| suse | linux_enterprise_desktop | 12.0:sp1 |
| suse | linux_enterprise_server | 12.0:sp1 |
| suse | linux_enterprise_software_development_kit | 12.0:sp1 |
| imagemagick | imagemagick | 𝑥 < 7.0.1-7 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| graphicsmagick |
| ||||||||||||
| imagemagick |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| graphicsmagick |
| ||||||||||||||||||
| imagemagick |
|