CVE-2016-5239
ImageMagick,GraphicsMagick: Gnuplot delegate vulnerability allowing command injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
La funcionalidad de delegación gnuplot en ImageMagick en versiones anteriores a 6.9.4-0 y GraphicsMagick permite a atacantes remotos ejecutar comandos arbitrarios a través de vectores no especificados.
It was discovered that ImageMagick did not properly sanitize certain input before passing it to the gnuplot delegate functionality. A remote attacker could create a specially crafted image that, when processed by an application using ImageMagick or an unsuspecting user using the ImageMagick utilities, would lead to arbitrary execution of shell commands with the privileges of the user running the application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-06-02 CVE Reserved
- 2016-06-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-284: Improper Access Control
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/91018 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://git.imagemagick.org/repos/ImageMagick/commit/70a2cf326ed32bedee144b961005c63846541a16 | 2018-08-04 | |
http://www.openwall.com/lists/oss-security/2016/06/02/13 | 2018-08-04 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2016:1237 | 2018-08-04 | |
https://access.redhat.com/security/cve/CVE-2016-5239 | 2016-06-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1334188 | 2016-06-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | <= 6.9.3-9 Search vendor "Imagemagick" for product "Imagemagick" and version " <= 6.9.3-9" | - |
Affected
|