Vulnerability Intelligence Report
ImageMagick Arbitrary File Deletion Vulnerability
CVE-2016-3715
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
5.5
MEDIUM
Exploitability:1.9
Impact Score:3.6
EPSS Probability:75.38%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-552 ↗CWE-552 Files or Directories Accessible to External Parties
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| redhat | enterprise_linux_desktop | 6.0, 7.0 |
| redhat | enterprise_linux_eus | 6.7, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7 |
| redhat | enterprise_linux_for_ibm_z_systems | 6.0_s390x, 7.0_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 6.7_s390x, 7.2_s390x, 7.3_s390x, 7.4_s390x, 7.5_s390x, 7.6_s390x, 7.7_s390x |
| redhat | enterprise_linux_for_power_big_endian | 6.0_ppc64, 7.0_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 6.7_ppc64, 7.2_ppc64, 7.3_ppc64, 7.4_ppc64, 7.5_ppc64, 7.6_ppc64, 7.7_ppc64 |
| redhat | enterprise_linux_for_power_little_endian | 7.0_ppc64le |
| redhat | enterprise_linux_for_power_little_endian_eus | 7.2_ppc64le, 7.3_ppc64le, 7.4_ppc64le, 7.5_ppc64le, 7.6_ppc64le, 7.7_ppc64le |
| redhat | enterprise_linux_hpc_node | 6.0, 7.0 |
| redhat | enterprise_linux_hpc_node_eus | 7.2 |
| redhat | enterprise_linux_server | 6.0, 7.0 |
| redhat | enterprise_linux_server_aus | 7.2, 7.3, 7.4, 7.6, 7.7 |
| redhat | enterprise_linux_server_from_rhui | 6.0, 7.0 |
| redhat | enterprise_linux_server_supplementary_eus | 6.7z |
| redhat | enterprise_linux_server_tus | 7.2, 7.3, 7.6, 7.7 |
| redhat | enterprise_linux_workstation | 6.0, 7.0 |
| imagemagick | imagemagick | 7.0.0-0, 7.0.1-0 |
| canonical | ubuntu_linux | 12.04, 14.04, 15.10, 16.04 |
| oracle | linux | 6, 7 |
| oracle | solaris | 10, 11.3 |
| suse | linux_enterprise_debuginfo | 11 |
| suse | manager | 2.1 |
| suse | manager_proxy | 2.1 |
| suse | openstack_cloud | 5 |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.2 |
| suse | linux_enterprise_desktop | 12 |
| suse | linux_enterprise_server | 11, 12 |
| suse | linux_enterprise_software_development_kit | 11, 12 |
| suse | linux_enterprise_workstation_extension | 12 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2016-03-30T00:00:00 |
| Published | 2016-05-05T18:00:00 |
| Patch Date | 2016-05-03 |
| Last Updated | 2025-10-21T23:55:52 |
Community Chatter & Buzz