FlawAtlas
Search the atlas
SUSE-SU-2016:1276-1 Not scored

Security update for GraphicsMagick

This update for GraphicsMagick fixes the following issues: - Security update Remote Code Execution / Local File read [bsc#978061] CVE-2016-3714, CVE-2016-3715, CVE-2016-3717, CVE-2016-3718 - CVE-2016-3714: Insufficient shell characters filtering leads to (potentially remote) code execution - CVE-2016-3715: Possible file deletion by using GraphicsMagick's 'tmp:' file specification syntax. - CVE-2016-3717: Possible local file read by using GraphicsMagick's 'txt:' file specification syntax. - CVE-2016-3718: Possible Server Side Request Forgery (SSRF) to make HTTP GET or FTP request.

Exploit probability Not scored
Published May 11, 2016
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Software Development Kit 11 SP4 GraphicsMagick
SUSE:Studio Onsite 1.3 GraphicsMagick

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2016:1276-1

This update for GraphicsMagick fixes the following issues: - Security update Remote Code Execution / Local File read [bsc#978061] CVE-2016-3714, CVE-2016-3715, CVE-2016-3717, CVE-2016-3718 - CVE-2016-3714: Insufficient shell characters filtering leads to (potentially remote) code execution - CVE-2016-3715: Possible file deletion by using GraphicsMagick's 'tmp:' file specification syntax. - CVE-2016-3717: Possible local file read by using GraphicsMagick's 'txt:' file specification syntax. - CVE-2016-3718: Possible Server Side Request Forgery (SSRF) to make HTTP GET or FTP request.

View original source

05 / REFERENCES

Further evidence