CVE-2016-3714
ImageMagick Improper Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 30 September 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
- CVSS 3.1
- 8.4 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 97.48% probability · 100th percentile
- CISA KEV
- Listed 9 September 2024 · due 30 September 2024
- Weakness
- CWE-20
- Affected
- imagemagick/imagemagick · canonical/ubuntu linux · debian/debian linux · opensuse/leap · opensuse/opensuse · suse/suse linux enterprise server
- Source
- secalert@redhat.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588#p132726, https://imagemagick.org/archive/releases/; https://nvd.nist.gov/vuln/detail/CVE-2016-3714
References
- http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLogPatch
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00041.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.htmlThird Party Advisory
- http://packetstormsecurity.com/files/152364/ImageTragick-ImageMagick-Proof-Of-Concepts.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-0726.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3580Third Party Advisory
- http://www.debian.org/security/2016/dsa-3746Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/03/13Mailing List
- http://www.openwall.com/lists/oss-security/2016/05/03/18Mailing List
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlThird Party Advisory
- http://www.rapid7.com/db/modules/exploit/unix/fileformat/imagemagick_delegateThird Party Advisory
- http://www.securityfocus.com/archive/1/538378/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/89848Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035742Third Party Advisory, VDB Entry
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568Third Party Advisory
- http://www.ubuntu.com/usn/USN-2990-1Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/2296071Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1332492Issue Tracking
- https://imagetragick.com/Vendor Advisory
- https://security.gentoo.org/glsa/201611-21Third Party Advisory
- https://www.exploit-db.com/exploits/39767/Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39791/Third Party Advisory, VDB Entry
- https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588Vendor Advisory
- https://www.imagemagick.org/script/changelog.phpVendor Advisory
- https://www.kb.cert.org/vuls/id/250519Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.