The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2016/06/02/13 | Mailing List Patch Third Party Advisory |
http://git.imagemagick.org/repos/ImageMagick/commit/70a2cf326ed32bedee144b961005c63846541a16 | Issue Tracking Patch Third Party Advisory |
http://www.securityfocus.com/bid/91018 | Third Party Advisory VDB Entry |
https://access.redhat.com/errata/RHSA-2016:1237 | |
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | |
https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html |
Configurations
Information
Published : 2017-03-15 12:59
Updated : 2018-08-03 18:29
NVD link : CVE-2016-5239
Mitre link : CVE-2016-5239
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
imagemagick
- imagemagick