CVE-2016-3718

Published May 5, 2016

Last updated 4 days ago

Overview

Description
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Source
secalert@redhat.com
NVD status
Analyzed
Products
enterprise_linux_desktop, enterprise_linux_eus, enterprise_linux_for_ibm_z_systems, enterprise_linux_for_ibm_z_systems_eus, enterprise_linux_for_power_big_endian, enterprise_linux_for_power_big_endian_eus, enterprise_linux_for_power_little_endian, enterprise_linux_for_power_little_endian_eus, enterprise_linux_hpc_node, enterprise_linux_hpc_node_eus, enterprise_linux_server, enterprise_linux_server_aus, enterprise_linux_server_from_rhui, enterprise_linux_server_supplementary_eus, enterprise_linux_server_tus, enterprise_linux_workstation, imagemagick, ubuntu_linux, linux, solaris, linux_enterprise_debuginfo, manager, manager_proxy, openstack_cloud, leap, opensuse, linux_enterprise_desktop, linux_enterprise_server, linux_enterprise_software_development_kit, linux_enterprise_workstation_extension

Risk scores

CVSS 3.1

Type
Primary
Base score
5.5
Impact score
3.6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:N/I:P/A:N

Known exploits

Data from CISA

Vulnerability name
ImageMagick Server-Side Request Forgery (SSRF) Vulnerability
Exploit added on
Nov 3, 2021
Exploit action due
May 3, 2022
Required action
Apply updates per vendor instructions.

Weaknesses

nvd@nist.gov
CWE-918
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-918

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.