Imagemagick Command Injection Vulnerability (CVE-2016-5118)
Imagemagick Command Injection Vulnerability (CVE-2016-5118)
Release date:
Updated on:
Affected Systems:
ImageMagick
Description:
CVE (CAN) ID: CVE-2016-5118
ImageMagick is an open-source image viewing and editing tool on Unix/Linux platforms.
ImageMagick uses (|) in filenames to cause a command injection vulnerability. You can grant the current user permission to execute arbitrary commands.
<* Source: Bob Friesenhahn
*>
Suggestion:
Vendor patch:
ImageMagick
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.imagemagick.org/
Https://www.debian.org/security/
Http://seclists.org/oss-sec/2016/q2/432
Use ImageMagick to draw a three-color schematic diagram
In Linux, PHP supports ImageMagick and MagicWandForPHP.
Image Magic with ImageMagick in Linux
Installation of ImageMagick and MagicWand For PHP in Linux
Install ImageMagick and JMagick in Linux
For details about ImageMagick, click here
ImageMagick: click here
This article permanently updates the link address: