SUSE-SU-2016:1301-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1301-1
SUSE-SU-2016:1301-1
Summary: Security update for ImageMagick
Details: This update for ImageMagick fixes the following issues: - bsc#978061: A vulnerability in ImageMagick's 'https' module allowed users to execute arbitrary shell commands on the host performing the image conversion. The issue had the potential for remote command injection. This update mitigates the vulnerability by disabling all access to the 'https' module in the 'delegates.xml' config file. (CVE-2016-3714)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161301-1/, https://bugzilla.suse.com/978061, https://www.suse.com/security/cve/CVE-2016-3714
Affected packages
Package
Name: ImageMagick
Purl: pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
