PT-2016-6248 · Imagemagick+6 · Imagemagick+6

CVE-2016-5118

·

Publicado

2016-05-30

·

Atualizado

2024-11-19

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions prior to 1.3.24 ImageMagick (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename, specifically through the OpenBlob function in blob.c.
Recommendations For GraphicsMagick versions prior to 1.3.24, update to version 1.3.24 or later to resolve the issue. For ImageMagick, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2016-1580
ALT-PU-2018-2652
CESA-2016_1237
CVE-2016-5118
DLA-500-1
DLA-502-1
DSA-3591-1
DSA-3746-1
MGASA-2016-0252
MGASA-2016-0257
OPENSUSE-SU-2016_1521-1
OPENSUSE-SU-2016_1522-1
OPENSUSE-SU-2016_1534-1
OPENSUSE-SU-2016_1653-1
OPENSUSE-SU-2016_3060-1
OPENSUSE-SU-2024:10040-1
OPENSUSE-SU-2024:10505-1
RHSA-2016:1237
RHSA-2016_1237
SUSE-SU-2016:1570-1
SUSE-SU-2016:1610-1
SUSE-SU-2016:1614-1
SUSE-SU-2016_1570-1
SUSE-SU-2016_1610-1
USN-2990-1

Produtos afetados

Alt Linux
Centos
Graphicsmagick
Imagemagick
Red Hat
Suse
Ubuntu