CVE Vulnerabilities

CVE-2016-3716

Published: May 05, 2016 | Modified: Apr 12, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical12.04 (including)12.04 (including)
Ubuntu_linuxCanonical14.04 (including)14.04 (including)
Ubuntu_linuxCanonical15.10 (including)15.10 (including)
Ubuntu_linuxCanonical16.04 (including)16.04 (including)
Red Hat Enterprise Linux 6RedHatImageMagick-0:6.7.2.7-4.el6_7*
Red Hat Enterprise Linux 7RedHatImageMagick-0:6.7.8.9-13.el7_2*
GraphicsmagickUbuntuartful*
GraphicsmagickUbuntuesm-apps/xenial*
GraphicsmagickUbuntuesm-infra-legacy/trusty*
GraphicsmagickUbuntuprecise*
GraphicsmagickUbuntutrusty*
GraphicsmagickUbuntutrusty/esm*
GraphicsmagickUbuntuwily*
GraphicsmagickUbuntuxenial*
GraphicsmagickUbuntuyakkety*
GraphicsmagickUbuntuzesty*
ImagemagickUbuntuartful*
ImagemagickUbuntubionic*
ImagemagickUbuntucosmic*
ImagemagickUbuntudevel*
ImagemagickUbuntuesm-infra-legacy/trusty*
ImagemagickUbuntuesm-infra/bionic*
ImagemagickUbuntuesm-infra/xenial*
ImagemagickUbuntuprecise*
ImagemagickUbuntutrusty*
ImagemagickUbuntutrusty/esm*
ImagemagickUbuntuwily*
ImagemagickUbuntuxenial*
ImagemagickUbuntuyakkety*
ImagemagickUbuntuzesty*

References