Back to Database
Status published
Critical
CVE-2016-5118
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and...
Vulnerability Description
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-5118
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2016:1237
- http://www.securitytracker.com/id/1035985
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00021.html
- http://hg.code.sf.net/p/graphicsmagick/code/rev/ae3928faa858
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00008.html
- http://www.securitytracker.com/id/1035984
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.securityfocus.com/bid/90938
- http://www.openwall.com/lists/oss-security/2016/05/30/1
- http://www.ubuntu.com/usn/USN-2990-1
- http://www.debian.org/security/2016/dsa-3591
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.397749
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00032.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.debian.org/security/2016/dsa-3746
- http://www.openwall.com/lists/oss-security/2016/05/29/7
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00009.html
- http://git.imagemagick.org/repos/ImageMagick/commit/40639d173aa8c76b850d625c630b711fee4dcfb8
- http://hg.code.sf.net/p/graphicsmagick/code/file/41876934e762/ChangeLog
More from graphicsmagick
View All →CVE-2020-21679
Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick...
Medium
5.5
CVE-2020-12672
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage...
High
7.5
CVE-2020-10938
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based...
Critical
9.8
CVE-2019-19953
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer...
Critical
9.1
CVE-2019-19951
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer...
Critical
9.8
Affected Vendor
graphicsmagick
View all reports →Affected Software
graphicsmagick, linux enterprise debuginfo, studio onsite, linux enterprise software development kit, solaris, linux, leap, opensuse, ubuntu linux, debian linux, linux enterprise desktop, linux enterprise server, linux enterprise workstation extension, imagemagick
Vulnerable Versions:
0, 11, 1.3, 12, 12.0, 10, 11.3, 6, 7, 42.1, 13.2, 12.04, 14.04, 15.10, 16.04, 8.0
Timeline
Official Publish:
June 10th, 2016
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.