HTTP: ImageMagick Delegate Command Injection
This signature detects attempts to exploit a known vulnerability ImageMagick. Attackers can inject code on the target system resulting in full control of the victim's computer.
Extended Description
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Affected Products
Imagemagick imagemagick
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Suse
Opensuse
Graphicsmagick
Oracle
Imagemagick
Debian
Canonical
10.0