PT-2016-2220 · Imagemagick+5 · Imagemagick+5
Nikolay Ermishkin
·
Published
2016-05-05
·
Updated
2025-04-02
·
CVE-2016-3715
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 6.9.3-10
ImageMagick versions 7.x prior to 7.0.1-1
Description
The issue is related to insufficient access control in the EPHEMERAL coder of the ImageMagick console graphic editor. It allows a remote attacker to delete arbitrary files using a specially crafted image.
Recommendations
For ImageMagick versions prior to 6.9.3-10, update to version 6.9.3-10 or later.
For ImageMagick versions 7.x prior to 7.0.1-1, update to version 7.0.1-1 or later.
As a temporary workaround, consider restricting access to the EPHEMERAL coder until a patch is available.
Exploit
Fix
Files Accessible to External Parties
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Imagemagick
Red Hat
Suse
Ubuntu