Vulnerability Name: | CVE-2016-5239 (CCN-114230) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2016-05-08 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2016-05-08 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2018-08-04 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-284 CWE-77 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-5239 Source: MISC Type: Issue Tracking, Patch, Third Party Advisory http://git.imagemagick.org/repos/ImageMagick/commit/70a2cf326ed32bedee144b961005c63846541a16 Source: CCN Type: RHSA-2016-1237 Important: ImageMagick security update Source: CCN Type: IBM Security Bulletin T1023934 (PowerKVM) Multiple vulnerabilities in ImageMagick affect PowerKVM Source: CCN Type: ImageMagick Web site Introduction to ImageMagick Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20160602 Re: ImageMagick CVEs Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html Source: BID Type: Third Party Advisory, VDB Entry 91018 Source: CCN Type: BID-91018 ImageMagick CVE-2016-5239 Command Injection Vulnerability Source: REDHAT Type: UNKNOWN RHSA-2016:1237 Source: CCN Type: Red Hat Bugzilla Bug 1334188 (CVE-2016-5239) CVE-2016-5239 ImageMagick,GraphicsMagick: Gnuplot delegate vulnerability allowing command injection Source: XF Type: UNKNOWN imagemagick-cve20165239-command-exec(114230) Source: CCN Type: ImageMagick GIT Repository ImageMagick Source: MLIST Type: UNKNOWN [debian-lts-announce] 20180803 [SECURITY] [DLA 1456-1] graphicsmagick security update | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Configuration RedHat 10: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |