CVE-2016-5118 describes a critical vulnerability in GraphicsMagick and ImageMagick, affecting various distributions like Debian, Oracle, and SUSE. This flaw, residing in the OpenBlob function, allows remote attackers to execute arbitrary code by injecting a pipe character at the beginning of a filename. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. Despite its high severity and EPSS score, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.23CPE matchmatch criteria | cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:suse:studio_onsite:1.3:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.