ZeroHour

CVE-2016-3715

KEV PoC ×2mass

Arbitrary File Deletion in ImageMagick via EPHEMERAL Coder (CVE-2016-3715)

CISA: ImageMagick Arbitrary File Deletion Vulnerability

CVSS 3.1
5.5 medium
EPSS
75%p99
Published
()
KEV added
AI analysis

CVE-2016-3715, one of the ImageTragick family of flaws disclosed in 2016, is a vulnerability in the EPHEMERAL coder of ImageMagick that allows an attacker to delete arbitrary files by tricking the library into processing a crafted image. The EPHEMERAL coder is designed to remove the file it processes when it finishes, and a crafted image can point this deletion at any file path accessible to the image-processing process. An attacker who gets a vulnerable ImageMagick instance to process a malicious image — for example via a website or service that accepts untrusted image uploads — can delete files with the privileges of that service, damaging data integrity and potentially breaking the application or system. Affected deployments include ImageMagick versions before 6.9.3-10 (6.x) and 7.x before 7.0.1-1, including versions packaged in Red Hat Enterprise Linux, SUSE/openSUSE, Ubuntu, and Oracle products. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03, a public proof of concept is available, and EPSS estimates a 75.4% probability of exploitation within 30 days.

What to do: Upgrade ImageMagick to 6.9.3-10 or later (6.x) or 7.0.1-1 or later (7.x), or apply the latest ImageMagick packages from Red Hat, SUSE, Canonical, or Oracle; applying vendor updates is CISA's required action for KEV. As an interim mitigation, deny the EPHEMERAL coder (and other nonessential coders) in ImageMagick's policy.xml and restrict processing to trusted inputs; prioritize internet-facing services that process untrusted image uploads.

Affected
ImageMagick6.x before 6.9.3-10 and 7.x before 7.0.1-1
Red Hat Enterprise Linux Desktop, Server, HPC Node, EUS, and Enterprise Linux for IBM Z Systems and for Power (big and little enpackaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via Red Hat errata (specific package versions not stated in source data)
Canonical Ubuntu (with affected ImageMagick packages)packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via vendor updates
Oracle Linux (with affected ImageMagick packages)packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via vendor updates
SUSE Linux Enterprise (with affected ImageMagick packages)packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via vendor updates
openSUSE (with affected ImageMagick packages)packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via vendor updates
Estimated exposure
masshundreds of thousands to millions of sites/servers (ImageMagick ships with most Linux distributions and web stacks, and public scans around the 2016 disclosure… — ImageMagick is bundled with virtually every major Linux distribution and used directly or via integrations (PHP imagick, CMS image pipelines, mail/web services) by a large share of web-facing servers, which public scanning at the time of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

CISA Known Exploited Vulnerability
Affected
ImageMagick ImageMagick
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
redhatimagemagickcanonicaloraclesuseopensuse
Products
enterprise linux desktop, enterprise linux eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power big endian, enterprise linux for power big endian eus, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus
Weakness
CWE-552
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.