CVE-2016-3718
Last modified
CVE-2016-3718 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.. CISA has confirmed active exploitation in the wild. EPSS estimates a 76.90% chance of exploitation in the next 30 days.
Description
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Desktop | 7.0 | — |
| Redhat | Enterprise Linux Eus | 6.7 | — |
| Redhat | Enterprise Linux Eus | 7.2 | — |
| Redhat | Enterprise Linux Eus | 7.3 | — |
| Redhat | Enterprise Linux Eus | 7.4 | — |
| Redhat | Enterprise Linux Eus | 7.5 | — |
| Redhat | Enterprise Linux Eus | 7.6 | — |
| Redhat | Enterprise Linux Eus | 7.7 | — |
| Redhat | Enterprise Linux For Ibm Z Systems | 6.0_s390x | — |
| Redhat | Enterprise Linux For Ibm Z Systems | 7.0_s390x | — |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 6.7_s390x | — |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 7.2_s390x | — |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 7.3_s390x | — |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 7.4_s390x | — |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 7.5_s390x | — |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 7.6_s390x | — |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 7.7_s390x | — |
| Redhat | Enterprise Linux For Power Big Endian | 6.0_ppc64 | — |
| Redhat | Enterprise Linux For Power Big Endian | 7.0_ppc64 | — |
| Redhat | Enterprise Linux For Power Big Endian Eus | 6.7_ppc64 | — |
| Redhat | Enterprise Linux For Power Big Endian Eus | 7.2_ppc64 | — |
| Redhat | Enterprise Linux For Power Big Endian Eus | 7.3_ppc64 | — |
| Redhat | Enterprise Linux For Power Big Endian Eus | 7.4_ppc64 | — |
| Redhat | Enterprise Linux For Power Big Endian Eus | 7.5_ppc64 | — |
| Redhat | Enterprise Linux For Power Big Endian Eus | 7.6_ppc64 | — |
| Redhat | Enterprise Linux For Power Big Endian Eus | 7.7_ppc64 | — |
| Redhat | Enterprise Linux For Power Little Endian | 7.0_ppc64le | — |
| Redhat | Enterprise Linux For Power Little Endian Eus | 7.2_ppc64le | — |
| Redhat | Enterprise Linux For Power Little Endian Eus | 7.3_ppc64le | — |
| Redhat | Enterprise Linux For Power Little Endian Eus | 7.4_ppc64le | — |
| Redhat | Enterprise Linux For Power Little Endian Eus | 7.5_ppc64le | — |
| Redhat | Enterprise Linux For Power Little Endian Eus | 7.6_ppc64le | — |
| Redhat | Enterprise Linux For Power Little Endian Eus | 7.7_ppc64le | — |
| Redhat | Enterprise Linux Hpc Node | 6.0 | — |
| Redhat | Enterprise Linux Hpc Node | 7.0 | — |
| Redhat | Enterprise Linux Hpc Node Eus | 7.2 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server | 7.0 | — |
| Redhat | Enterprise Linux Server Aus | 7.2 | — |
| Redhat | Enterprise Linux Server Aus | 7.3 | — |
| Redhat | Enterprise Linux Server Aus | 7.4 | — |
| Redhat | Enterprise Linux Server Aus | 7.6 | — |
| Redhat | Enterprise Linux Server Aus | 7.7 | — |
| Redhat | Enterprise Linux Server From Rhui | 6.0 | — |
| Redhat | Enterprise Linux Server From Rhui | 7.0 | — |
| Redhat | Enterprise Linux Server Supplementary Eus | 6.7z | — |
| Redhat | Enterprise Linux Server Tus | 7.2 | — |
| Redhat | Enterprise Linux Server Tus | 7.3 | — |
| Redhat | Enterprise Linux Server Tus | 7.6 | — |
Showing 50 of 76 affected configurations. See NVD for the full list.
References
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0726.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3580Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/03/18Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/538378/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2990-1Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00009.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201611-21Third Party Advisory
- https://www.exploit-db.com/exploits/39767/Third Party Advisory, VDB Entry
- https://www.imagemagick.org/script/changelog.phpRelease Notes
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0726.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3580Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/03/18Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/538378/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2990-1Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00009.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201611-21Third Party Advisory
- https://www.exploit-db.com/exploits/39767/Third Party Advisory, VDB Entry
- https://www.imagemagick.org/script/changelog.phpRelease Notes
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3718US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2016-3718?
How severe is CVE-2016-3718?
How do I fix CVE-2016-3718?
Are you affected by CVE-2016-3718?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
