CVE-2016-5118: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 50% chance of exploitation in the next 30 days.
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Graphicsmagick Graphicsmagick: up to and including 1.3.23
- ImageMagick ImageMagick: before 7.0.1-7 (fixed in 7.0.1-7)
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
- Oracle Linux: version 6 only; version 7 only
- Oracle Solaris: version 10 only; version 11.3 only
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Desktop: version 12 only; version 12.0 only
- Suse Linux Enterprise Server: version 12 only; version 12.0 only
- Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only; version 12.0 only
- Suse Linux Enterprise Workstation Extension: version 12 only
- Suse Studio Onsite: version 1.3 only
Published 2016-06-10. Last modified 2026-06-17.