Executive brief
The EPHEMERAL coder in ImageMagick allows remote attackers to delete arbitrary files via a crafted image. This occurs because the 'ephemeral' pseudo protocol deletes files after reading them, which can be exploited if an attacker can trigger the processing of a malicious image.
Affected products
- ImageMagick Studio LLC ImageMagick before 6.9.3-10, 7.x before 7.0.1-1
Timeline
- 2016-05-03: disclosed: Initial public disclosure via oss-security list
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog