CVE-2016-3716: Canonical Ubuntu Linux

Low severity, CVSS 3.3. EPSS: 11.3% chance of exploitation in the next 30 days.

The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • ImageMagick ImageMagick: up to and including 6.9.3-9; version 7.0.0-0 only; version 7.0.1-0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Hpc Node: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Hpc Node Eus: version 7.2 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.2 only
  • Red Hat Enterprise Linux Server Eus: version 7.2 only
  • Red Hat Enterprise Linux Server Supplementary Eus: version 6.7z only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2016-05-05. Last modified 2026-06-17.