CVE-2016-5118
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
- Affected products
- Alt Linux, Centos, Graphicsmagick, Imagemagick, Red Hat, Suse, Ubuntu
- Graphicsmagick
- ≤ 1.3.23
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 50.0% (99th percentile)
- NVD status
- Modified
- Published
- 2016-06-10
CVE-2016-5118 at NVD
1 known exploit for CVE-2016-5118
Proof-of-concept code and exploit modules indexed by Sploitus