HTTP: ImageMagick Delegate Command Injection

This signature detects attempts to exploit a known vulnerability ImageMagick. Attackers can inject code on the target system resulting in full control of the victim's computer.

Extended Description

The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

Affected Products

Imagemagick imagemagick

Short Name
HTTP:IMAGEMAGICK-COMM-INJ
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2016-3714 CVE-2016-5118 Command Delegate ImageMagick Injection
Release Date
06/09/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3814
False Positive
Occasionally
Vendors

Suse

Opensuse

Graphicsmagick

Oracle

Imagemagick

Debian

Canonical

CVSS Score

10.0

Found a potential security threat?