Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2016-3716

Severity
3.3LOW
EPSS
24.3%
top 3.90%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 5
Latest updateMay 14

Description

The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages7 packages

Debianimagemagick< 8:6.9.6.2+dfsg-2+3
Debiangraphicsmagick< 1.3.24-1+3

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04, Enterprise Linux 7.2, 6.7z

Patches

🔴Vulnerability Details

4
GHSA
GHSA-28g7-m47w-h853: The MSL coder in ImageMagick before 62022-05-14
OSV
imagemagick vulnerabilities2016-06-02
OSV
CVE-2016-3716: The MSL coder in ImageMagick before 62016-05-05
CVEList
CVE-2016-3716: The MSL coder in ImageMagick before 62016-05-05

💥Exploits & PoCs

1
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities2016-05-04

🔍Detection Rules

1
Suricata
ET WEB_SERVER ImageMagick CVE-2016-3716 Move File Inbound (msl: + mvg)2016-05-04

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2016-06-02
Red Hat
ImageMagick: File moving2016-05-03
Debian
CVE-2016-3716: graphicsmagick - The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remot...2016

💬Community

2
Bugzilla
CVE-2016-3716 ImageMagick: File moving2016-05-03
Bugzilla
CVE-2016-3716 ImageMagick: File moving [fedora-all]2016-05-03
CVE-2016-3716 (LOW CVSS 3.3) | The MSL coder in ImageMagick before | cvebase.io