CVE-2016-3715
KEV PoC ×2massArbitrary File Deletion in ImageMagick via EPHEMERAL Coder (CVE-2016-3715)
CISA: ImageMagick Arbitrary File Deletion Vulnerability
CVE-2016-3715, one of the ImageTragick family of flaws disclosed in 2016, is a vulnerability in the EPHEMERAL coder of ImageMagick that allows an attacker to delete arbitrary files by tricking the library into processing a crafted image. The EPHEMERAL coder is designed to remove the file it processes when it finishes, and a crafted image can point this deletion at any file path accessible to the image-processing process. An attacker who gets a vulnerable ImageMagick instance to process a malicious image — for example via a website or service that accepts untrusted image uploads — can delete files with the privileges of that service, damaging data integrity and potentially breaking the application or system. Affected deployments include ImageMagick versions before 6.9.3-10 (6.x) and 7.x before 7.0.1-1, including versions packaged in Red Hat Enterprise Linux, SUSE/openSUSE, Ubuntu, and Oracle products. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03, a public proof of concept is available, and EPSS estimates a 75.4% probability of exploitation within 30 days.
What to do: Upgrade ImageMagick to 6.9.3-10 or later (6.x) or 7.0.1-1 or later (7.x), or apply the latest ImageMagick packages from Red Hat, SUSE, Canonical, or Oracle; applying vendor updates is CISA's required action for KEV. As an interim mitigation, deny the EPHEMERAL coder (and other nonessential coders) in ImageMagick's policy.xml and restrict processing to trusted inputs; prioritize internet-facing services that process untrusted image uploads.
| ImageMagick | 6.x before 6.9.3-10 and 7.x before 7.0.1-1 |
| Red Hat Enterprise Linux Desktop, Server, HPC Node, EUS, and Enterprise Linux for IBM Z Systems and for Power (big and little en | packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via Red Hat errata (specific package versions not stated in source data) |
| Canonical Ubuntu (with affected ImageMagick packages) | packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via vendor updates |
| Oracle Linux (with affected ImageMagick packages) | packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via vendor updates |
| SUSE Linux Enterprise (with affected ImageMagick packages) | packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via vendor updates |
| openSUSE (with affected ImageMagick packages) | packaged ImageMagick vulnerable in versions before 6.9.3-10 / 7.0.1-1; fixed via vendor updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
- Affected
- ImageMagick ImageMagick
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- redhatimagemagickcanonicaloraclesuseopensuse
- Products
- enterprise linux desktop, enterprise linux eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power big endian, enterprise linux for power big endian eus, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus
- Weakness
- CWE-552
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.