peter bassill · operator
$ cve CVE-2016-5118 JSON

CVE-2016-5118

9.8
CRITICAL · CVSS 3.1 · EPSS 50% (pctl 99)

Patch early

EPSS 50% — above the 10% action threshold.

Description

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS49.98% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploitnone known
Published2016-06-10
Last modified2026-06-17

Affected (14)

VendorProduct
canonicalubuntu linux
debiandebian linux
graphicsmagickgraphicsmagick
imagemagickimagemagick
opensuseleap
opensuseopensuse
oraclelinux
oraclesolaris
suselinux enterprise debuginfo
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit
suselinux enterprise workstation extension
susestudio onsite

References

→ the Explorer  ·  watch your stack  ·  NVD