5.8
CVE-2016-3715
- EPSS 75.38%
- Veröffentlicht 05.05.2016 18:59:04
- Zuletzt bearbeitet 22.04.2026 14:35:10
- Erkennungen
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 6.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 7.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 6.7_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.2_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.3_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.4_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.5_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.6_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.7_s390x
Redhat ≫ Enterprise Linux For Power Big Endian Version 6.0_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Version 7.0_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 6.7_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.2_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.3_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.4_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.5_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.6_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.7_ppc64
Redhat ≫ Enterprise Linux For Power Little Endian Version 7.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.2_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.3_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.4_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.5_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.6_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.7_ppc64le
Redhat ≫ Enterprise Linux Hpc Node Version 6.0
Redhat ≫ Enterprise Linux Hpc Node Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Eus Version 7.2
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.2
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 7.7
Redhat ≫ Enterprise Linux Server From Rhui Version 6.0
Redhat ≫ Enterprise Linux Server From Rhui Version 7.0
Redhat ≫ Enterprise Linux Server Supplementary Eus Version 6.7z
Redhat ≫ Enterprise Linux Server Tus Version 7.2
Redhat ≫ Enterprise Linux Server Tus Version 7.3
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Imagemagick ≫ Imagemagick Version < 6.9.3-10
Imagemagick ≫ Imagemagick Version 7.0.0-0
Imagemagick ≫ Imagemagick Version 7.0.1-0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.10
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp2
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp3
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Manager Proxy Version 2.1
Suse ≫ Openstack Cloud Version 5
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Server Version 12 Update sp1
Suse ≫ Linux Enterprise Software Development Kit Version 11 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update -
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update sp1
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update -
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp1
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
ImageMagick Arbitrary File Deletion Vulnerability
SchwachstelleImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 75.38% | 0.995 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:P
|
| CISA-ADP | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLog
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.html
http://rhn.redhat.com/errata/RHSA-2016-0726.html
http://www.debian.org/security/2016/dsa-3580
http://www.debian.org/security/2016/dsa-3746
http://www.openwall.com/lists/oss-security/2016/05/03/18
http://www.securityfocus.com/archive/1/538378/100/0/threaded
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568
http://www.ubuntu.com/usn/USN-2990-1
https://security.gentoo.org/glsa/201611-21
https://www.exploit-db.com/exploits/39767/
https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588
https://www.imagemagick.org/script/changelog.php
http://www.securityfocus.com/bid/89852
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3715