ImageTragick
ImageMagick Is On Fire―CVE-2016-3714
TL;DR
There are multiple vulnerabilities in ImageMagick, a package commonly used by web services to process images.
One of the vulnerabilities can lead to remote code execution (RCE) if you process user submitted images. The exploit for this vulnerability is being used in the wild.
以下ソース参照
https://imagetragick.com/
脆弱性が修正されたバージョン(7.0.1-1 と 6.9.3-10)は今週末にリリース予定なので、それまでは上のサイトにある policy.xml で対応する必要がある
PCI DSS 3.2公開、脆弱性抱えたWinXPやVistaでのカード決済も2018年までは認める
http://itpro.nikkeibp.co.jp/atcl/column/14/346926/042200515/
VIPQ2_EXTDAT: default:default:VIP931931:512:----: EXT was configured