Vulnerability Bulletins

DSA-3580 imagemagick - security update

   
Affected software Debian
 
Nikolay Ermishkin from the Mail.Ru Security Team and Stewie discoveredseveral vulnerabilities in ImageMagick, a program suite for imagemanipulation. These vulnerabilities, collectively known as ImageTragick,are the consequence of lack of sanitization of untrusted input. Anattacker with control on the image input could, with the privileges ofthe user running the application, execute code(CVE-2016-3714), make HTTPGET or FTP requests (CVE-2016-3718),or delete (CVE-2016-3715), move(CVE-2016-3716),

More info:

https://www.debian.org/security/2016/dsa-3580