Total vulnerabilities in the database
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Software | From | Fixed in |
---|---|---|
graphicsmagick / graphicsmagick | - | 1.3.23.x |
suse / studio_onsite | 1.3 | 1.3.x |
suse / linux_enterprise_software_development_kit | 11-sp4 | 11-sp4.x |
suse / linux_enterprise_debuginfo | 11-sp4 | 11-sp4.x |
oracle / solaris | 11.3 | 11.3.x |
oracle / solaris | 10 | 10.x |
oracle / linux | 6 | 6.x |
oracle / linux | 7 | 7.x |
opensuse / leap | 42.1 | 42.1.x |
opensuse / opensuse | 13.2 | 13.2.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 15.10 | 15.10.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
debian / debian_linux | 8.0 | 8.0.x |
suse / linux_enterprise_desktop | 12.0-sp1 | 12.0-sp1.x |
suse / linux_enterprise_software_development_kit | 12.0-sp1 | 12.0-sp1.x |
suse / linux_enterprise_server | 12.0-sp1 | 12.0-sp1.x |
suse / linux_enterprise_workstation_extension | 12-sp1 | 12-sp1.x |
suse / linux_enterprise_server | 12 | 12.x |
suse / linux_enterprise_software_development_kit | 12 | 12.x |
suse / linux_enterprise_desktop | 12 | 12.x |
suse / linux_enterprise_workstation_extension | 12 | 12.x |