FlawAtlas
Search the atlas
SUSE-SU-2016:1301-1 Not scored

Security update for ImageMagick

This update for ImageMagick fixes the following issues: - bsc#978061: A vulnerability in ImageMagick's 'https' module allowed users to execute arbitrary shell commands on the host performing the image conversion. The issue had the potential for remote command injection. This update mitigates the vulnerability by disabling all access to the 'https' module in the 'delegates.xml' config file. (CVE-2016-3714)

Exploit probability Not scored
Published May 13, 2016
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 11 SP2-LTSS ImageMagick
SUSE:Linux Enterprise Server 11 SP3-LTSS ImageMagick
SUSE:Linux Enterprise Server 11 SP3-TERADATA ImageMagick
SUSE:Linux Enterprise Server 11 SP4 ImageMagick
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 ImageMagick
SUSE:Linux Enterprise Software Development Kit 11 SP4 ImageMagick
SUSE:Manager 2.1 ImageMagick
SUSE:Manager Proxy 2.1 ImageMagick
SUSE:OpenStack Cloud 5 ImageMagick

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2016:1301-1

This update for ImageMagick fixes the following issues: - bsc#978061: A vulnerability in ImageMagick's 'https' module allowed users to execute arbitrary shell commands on the host performing the image conversion. The issue had the potential for remote command injection. This update mitigates the vulnerability by disabling all access to the 'https' module in the 'delegates.xml' config file. (CVE-2016-3714)

View original source

05 / REFERENCES

Further evidence