CVE-2016-5118
Description
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
31.781
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.1-7 | Windows |
| Multiple Vulnerabilities are affected in Imagemagic 7.0.1-7 | Windows |
| Multiple Vulnerabilities are affected in ImageMagick 7.0.1-7 | Windows |
| imagemagick security update(DSA-3591-1) imagemagick_6.8.9.9-5+deb8u3_amd64.deb | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-6.7.8.9-15.el7_2.i686.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-c++-6.7.8.9-15.el7_2.i686.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-c++-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-doc-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-perl-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-devel-6.7.8.9-15.el7_2.i686.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-devel-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-c++-devel-6.7.8.9-15.el7_2.i686.rpm | Linux |
| Imagemagick security update (CESA-2016:1237) ImageMagick-c++-devel-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-6.7.2.7-5.el6_8.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-6.7.2.7-5.el6_8.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-6.7.8.9-15.el7_2.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-c++-6.7.2.7-5.el6_8.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-c++-6.7.2.7-5.el6_8.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-c++-6.7.8.9-15.el7_2.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-c++-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-c++-devel-6.7.2.7-5.el6_8.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-c++-devel-6.7.2.7-5.el6_8.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-c++-devel-6.7.8.9-15.el7_2.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-c++-devel-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-devel-6.7.2.7-5.el6_8.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-devel-6.7.2.7-5.el6_8.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-devel-6.7.8.9-15.el7_2.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-devel-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-doc-6.7.2.7-5.el6_8.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-doc-6.7.2.7-5.el6_8.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-doc-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-perl-6.7.2.7-5.el6_8.i686.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-perl-6.7.2.7-5.el6_8.x86_64.rpm | Linux |
| (RHSA-2016:1237) Important: ImageMagick security update ImageMagick-perl-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) ImageMagick-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) ImageMagick-debuginfo-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) ImageMagick-debugsource-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) libMagick++-6_Q16-3-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) libMagick++-6_Q16-3-debuginfo-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) libMagickCore-6_Q16-1-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) libMagickCore-6_Q16-1-32bit-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) libMagickCore-6_Q16-1-debuginfo-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) libMagickCore-6_Q16-1-debuginfo-32bit-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) libMagickWand-6_Q16-1-6.8.8.1-25.1.x86_64.rpm | Linux |
| SUSE-SU-2016:1570-1(SUSE Linux Enterprise Desktop 12 ) libMagickWand-6_Q16-1-debuginfo-6.8.8.1-25.1.x86_64.rpm | Linux |
| ImageMagick update (ELSA-2016-1237) ImageMagick-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| ImageMagick-c++ update (ELSA-2016-1237) ImageMagick-c++-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| ImageMagick-c++-devel update (ELSA-2016-1237) ImageMagick-c++-devel-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| ImageMagick-devel update (ELSA-2016-1237) ImageMagick-devel-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| ImageMagick-doc update (ELSA-2016-1237) ImageMagick-doc-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| ImageMagick-perl update (ELSA-2016-1237) ImageMagick-perl-6.7.8.9-15.el7_2.x86_64.rpm | Linux |
| ImageMagick update (ELSA-2016-1237) ImageMagick-6.7.8.9-15.el7_2.i686.rpm | Linux |
| ImageMagick-c++ update (ELSA-2016-1237) ImageMagick-c++-6.7.8.9-15.el7_2.i686.rpm | Linux |
| ImageMagick-c++-devel update (ELSA-2016-1237) ImageMagick-c++-devel-6.7.8.9-15.el7_2.i686.rpm | Linux |
| ImageMagick-devel update (ELSA-2016-1237) ImageMagick-devel-6.7.8.9-15.el7_2.i686.rpm | Linux |
| CVE-2016-5118 | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234