Lucene search

K
hackeroneStewieH1:143966
HistoryApr 21, 2016 - 12:00 a.m.

Internet Bug Bounty: Insufficient shell characters filtering leads to (potentially remote) code execution (CVE-2016-3714)

2016-04-2100:00:00
stewie
hackerone.com
46

0.967 High

EPSS

Percentile

99.7%

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka โ€œImageTragick.โ€

See also:
http://www.openwall.com/lists/oss-security/2016/05/03/18
https://imagetragick.com/