CVE-2016-3715
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
ImageMagick's EPHEMERAL coder had a flaw that allowed attackers to delete files on a system by uploading a specially crafted image. This is dangerous because it could lead to loss of important data or system instability.
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 is vulnerable to arbitrary file deletion via malicious image input. An attacker can craft a specially formatted image file that, when processed by the vulnerable coder, results in deletion of arbitrary files with the privileges of the ImageMagick process. This requires the application to process untrusted image files without proper validation.
The full analysis of this CVE is available in Portuguese →