First published: Thu May 05 2016(Updated: )
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | ||
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =6.7 | |
redhat enterprise Linux eus | =7.2 | |
redhat enterprise Linux eus | =7.3 | |
redhat enterprise Linux eus | =7.4 | |
redhat enterprise Linux eus | =7.5 | |
redhat enterprise Linux eus | =7.6 | |
redhat enterprise Linux eus | =7.7 | |
redhat enterprise Linux for ibm z systems | =6.0_s390x | |
redhat enterprise Linux for ibm z systems | =7.0_s390x | |
redhat enterprise Linux for ibm z systems eus | =6.7_s390x | |
redhat enterprise Linux for ibm z systems eus | =7.2_s390x | |
redhat enterprise Linux for ibm z systems eus | =7.3_s390x | |
redhat enterprise Linux for ibm z systems eus | =7.4_s390x | |
redhat enterprise Linux for ibm z systems eus | =7.5_s390x | |
redhat enterprise Linux for ibm z systems eus | =7.6_s390x | |
redhat enterprise Linux for ibm z systems eus | =7.7_s390x | |
redhat enterprise Linux for power big endian | =6.0_ppc64 | |
redhat enterprise Linux for power big endian | =7.0_ppc64 | |
redhat enterprise Linux for power big endian eus | =6.7_ppc64 | |
redhat enterprise Linux for power big endian eus | =7.2_ppc64 | |
redhat enterprise Linux for power big endian eus | =7.3_ppc64 | |
redhat enterprise Linux for power big endian eus | =7.4_ppc64 | |
redhat enterprise Linux for power big endian eus | =7.5_ppc64 | |
redhat enterprise Linux for power big endian eus | =7.6_ppc64 | |
redhat enterprise Linux for power big endian eus | =7.7_ppc64 | |
redhat enterprise Linux for power little endian | =7.0_ppc64le | |
redhat enterprise Linux for power little endian eus | =7.2_ppc64le | |
redhat enterprise Linux for power little endian eus | =7.3_ppc64le | |
redhat enterprise Linux for power little endian eus | =7.4_ppc64le | |
redhat enterprise Linux for power little endian eus | =7.5_ppc64le | |
redhat enterprise Linux for power little endian eus | =7.6_ppc64le | |
redhat enterprise Linux for power little endian eus | =7.7_ppc64le | |
Red Hat Enterprise Linux HPC Node | =6.0 | |
Red Hat Enterprise Linux HPC Node | =7.0 | |
Red Hat Enterprise Linux HPC Node | =7.2 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.2 | |
redhat enterprise Linux server aus | =7.3 | |
redhat enterprise Linux server aus | =7.4 | |
redhat enterprise Linux server aus | =7.6 | |
redhat enterprise Linux server aus | =7.7 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =7.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.7z | |
redhat enterprise Linux server tus | =7.2 | |
redhat enterprise Linux server tus | =7.3 | |
redhat enterprise Linux server tus | =7.6 | |
redhat enterprise Linux server tus | =7.7 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
ImageMagick ImageMagick | <6.9.3-10 | |
ImageMagick ImageMagick | =7.0.0-0 | |
ImageMagick ImageMagick | =7.0.1-0 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =15.10 | |
Ubuntu | =16.04 | |
Oracle Linux | =6 | |
Oracle Linux | =7 | |
Oracle Solaris SPARC | =10 | |
Oracle Solaris SPARC | =11.3 | |
SUSE Linux Enterprise Debuginfo | =11-sp2 | |
SUSE Linux Enterprise Debuginfo | =11-sp3 | |
SUSE Linux Enterprise Debuginfo | =11-sp4 | |
SUSE Manager | =2.1 | |
suse manager proxy | =2.1 | |
openSUSE OpenStack Cloud | =5 | |
openSUSE | =42.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Desktop with Beagle | =12 | |
SUSE Linux Enterprise Desktop with Beagle | =12-sp1 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12 | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE Linux Enterprise Software Development Kit | =11-sp4 | |
SUSE Linux Enterprise Software Development Kit | =12 | |
SUSE Linux Enterprise Software Development Kit | =12-sp1 | |
SUSE Linux Enterprise Workstation Extension | =12 | |
SUSE Linux Enterprise Workstation Extension | =12-sp1 | |
redhat enterprise Linux server eus | =7.2 | |
ImageMagick ImageMagick | <=6.9.3-9 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 |
http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLog
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3715 is classified as a high severity vulnerability due to its potential to allow remote attackers to delete arbitrary files.
To fix CVE-2016-3715, update ImageMagick to versions 6.9.3-10 or later, or 7.0.1-1 or later.
CVE-2016-3715 affects various versions of ImageMagick and specific releases of Red Hat Enterprise Linux, Ubuntu, and Oracle Linux.
Attackers exploiting CVE-2016-3715 can potentially delete critical files on the server, compromising the integrity and availability of the system.
CVE-2016-3715 is a remote vulnerability, allowing attackers to cause damage without direct access to the target system.