First published: Mon May 09 2016(Updated: )
It was found that gnuplot delegate functionality in ImageMagick and GraphicsMagick allows system command injection while interpreting gnuplot files. Upstream patch (ImageMagick): <a href="http://git.imagemagick.org/repos/ImageMagick/commit/70a2cf326ed32bedee144b961005">http://git.imagemagick.org/repos/ImageMagick/commit/70a2cf326ed32bedee144b961005</a> Upstream patch (GraphicsMagick): <a href="http://hg.code.sf.net/p/graphicsmagick/code/rev/45998a25992d">http://hg.code.sf.net/p/graphicsmagick/code/rev/45998a25992d</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <=6.9.3-9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.