[Forgot Password]
Login  Register Subscribe

24128

 
 

131573

 
 

110139

 
 

909

 
 

85964

 
 

136

Paid content will be excluded from the download.


Download | Alert*
OVAL

Command injection vulnerability in ImageMagick

ID: oval:org.secpod.oval:def:35563Date: (C)2016-06-14   (M)2018-06-04
Class: VULNERABILITYFamily: unix




The host is installed with RHEL 6 or 7 and is prone to a command injection vulnerability. A flaw is present in the application, which fails to properly sanitize certain input before passing it to the gnuplot delegate functionality. Successful exploitation could allow attackers to execute arbitrary code.

Platform:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Product:
ImageMagick
Reference:
CVE-2016-5239
CVE    1
CVE-2016-5239
CPE    3
cpe:/o:redhat:enterprise_linux:7
cpe:/a:imagemagick:imagemagick
cpe:/o:redhat:enterprise_linux:6

© SecPod Technologies