Vulnerability Bulletins |
DSA-3580 imagemagick - security update |
|
| Affected software | Debian |
|
Nikolay Ermishkin from the Mail.Ru Security Team and Stewie discoveredseveral vulnerabilities in ImageMagick, a program suite for imagemanipulation. These vulnerabilities, collectively known as ImageTragick,are the consequence of lack of sanitization of untrusted input. Anattacker with control on the image input could, with the privileges ofthe user running the application, execute code(CVE-2016-3714), make HTTPGET or FTP requests (CVE-2016-3718),or delete (CVE-2016-3715), move(CVE-2016-3716), More info: https://www.debian.org/security/2016/dsa-3580 |
|






