CVE-2016-3717
published 2016-05-05CVE-2016-3717: The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
PriorityP351medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EXPLOIT
EPSS
20.44%
97.2th percentile
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | graphicsmagick | < graphicsmagick 1.3.24-1 (bookworm) | graphicsmagick 1.3.24-1 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.3.24-1 (bookworm) | graphicsmagick 1.3.24-1 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.24-1 | 1.3.24-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.24-1 | 1.3.24-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.24-1 | 1.3.24-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.24-1 | 1.3.24-1 |
| imagemagick | imagemagick | <= 6.9.3-9 | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.1 | 8:6.7.7.10-6ubuntu3.1 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.1 | 8:6.8.9.9-7ubuntu5.1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
osv8.4HIGH
vendor_ubuntu8.4HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2016-06-02·CVSS 8.4
CVE-2016-3714 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
Nikolay Ermishkin and Stewie discovered that ImageMagick incorrectly
sanitized untrusted input. A remote attacker could use these issues to
execute arbitrary code. These issues are known as "ImageTragick". This
update disables problematic coders via the /etc/ImageMagick-6/policy.xml
configuration file. In certain environments the coders may need to be
manually re-enabled after making sure that ImageMagick does not process
untrusted input. (CVE-2016-3714, CVE-2016-3715, CVE-2016-3716,
CVE-2016-3717, CVE-2016-3718)
Bob Friesenhahn discovered that ImageMagick allowed injecting commands via
an image file or filename. A remote attacker could use this issue to
execute arbitrary code. (CVE-2016-5118)
Red Hat
ImageMagick: Local file read
vendor_redhat·2016-05-03·CVSS 5.5
CVE-2016-3717 [MEDIUM] CWE-20 ImageMagick: Local file read
ImageMagick: Local file read
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
It was discovered that certain ImageMagick coders and pseudo-protocols did not properly prevent security sensitive operations when processing specially crafted images. A remote attacker could create a specially crafted image that, when processed by an application using ImageMagick or an unsuspecting user using the ImageMagick utilities, would allow the attacker to disclose the contents of arbitrary files.
Mitigation: Details can be found under the resolve tab at https://access.redhat.com/security/vulnerabilities/2296071
Red Hat Enterprise Linux 6 and 7
As a workaround the /etc/ImageMagick/policy.xml file can be edited to
Debian
CVE-2016-3717: graphicsmagick - The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows rem...
vendor_debian·2016·CVSS 5.5
CVE-2016-3717 [MEDIUM] CVE-2016-3717: graphicsmagick - The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows rem...
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3.24-1)
GHSA
GHSA-cc28-64rq-q7jg: The LABEL coder in ImageMagick before 6
ghsa_unreviewed·2022-05-14
CVE-2016-3717 [HIGH] CWE-200 GHSA-cc28-64rq-q7jg: The LABEL coder in ImageMagick before 6
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
OSV
imagemagick vulnerabilities
osv·2016-06-02·CVSS 8.4
CVE-2016-3714 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
Nikolay Ermishkin and Stewie discovered that ImageMagick incorrectly
sanitized untrusted input. A remote attacker could use these issues to
execute arbitrary code. These issues are known as "ImageTragick". This
update disables problematic coders via the /etc/ImageMagick-6/policy.xml
configuration file. In certain environments the coders may need to be
manually re-enabled after making sure that ImageMagick does not process
untrusted input. (CVE-2016-3714, CVE-2016-3715, CVE-2016-3716,
CVE-2016-3717, CVE-2016-3718)
Bob Friesenhahn discovered that ImageMagick allowed injecting commands via
an image file or filename. A remote attacker could use this issue to
execute arbitrary code. (CVE-2016-5118)
OSV
CVE-2016-3717: The LABEL coder in ImageMagick before 6
osv·2016-05-05·CVSS 5.5
CVE-2016-3717 [MEDIUM] CVE-2016-3717: The LABEL coder in ImageMagick before 6
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
Suricata
ET WEB_SERVER ImageMagick CVE-2016-3717 Local File Read Inbound (label: + mvg)
suricata·2016-05-04·CVSS 5.5
CVE-2016-3717 [MEDIUM] ET WEB_SERVER ImageMagick CVE-2016-3717 Local File Read Inbound (label: + mvg)
ET WEB_SERVER ImageMagick CVE-2016-3717 Local File Read Inbound (label: + mvg)
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER ImageMagick CVE-2016-3717 Local File Read Inbound (label: + mvg)"; flow:established,to_server; http.request_body; content:"viewbox|20|"; nocase; fast_pattern; content:"label"; nocase; pcre:"/^\s*\x3a\s*\x40/Ri"; classtype:web-application-attack; sid:2022794; rev:5; metadata:created_at 2016_05_04, cve CVE_2016_3717, signature_severity Major, updated_at 2020_10_06;)
Bugzilla
CVE-2016-3717 ImageMagick: Local file read
bugzilla·2016-05-03·CVSS 5.5
CVE-2016-3717 [MEDIUM] CVE-2016-3717 ImageMagick: Local file read
CVE-2016-3717 ImageMagick: Local file read
A vulnerability was found in ImageMagick. It is possible to get content of the files from the server by using ImageMagick's 'label' pseudo protocol.
Discussion:
Mitigation:
Details can be found under the resolve tab at https://access.redhat.com/security/vulnerabilities/2296071
Red Hat Enterprise Linux 6 and 7
As a workaround the /etc/ImageMagick/policy.xml file can be edited to disable processing of MVG, HTTPS, HTTP, URL, FTP, EPHEMERAL, MSL, LABEL, TEXT,
SHOW, WIN and PLT commands within image files, simply add the following lines:
within the policy map stanza:
...
Red Hat Enterprise Linux 5
In the following folders:
/usr/lib64/ImageMagick-6.2.8/modules-Q16/coders/ (64bit package)
or
/usr/lib/ImageMagick-6.2.8/modules-Q16/coders/ (32
Bugzilla
CVE-2016-3717 ImageMagick: Local file read [fedora-all]
bugzilla·2016-05-03·CVSS 5.5
CVE-2016-3717 [MEDIUM] CVE-2016-3717 ImageMagick: Local file read [fedora-all]
CVE-2016-3717 ImageMagick: Local file read [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one
http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLoghttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0726.htmlhttp://www.debian.org/security/2016/dsa-3580http://www.openwall.com/lists/oss-security/2016/05/03/18http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/archive/1/538378/100/0/threadedhttp://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568http://www.ubuntu.com/usn/USN-2990-1https://lists.debian.org/debian-lts-announce/2018/06/msg00009.htmlhttps://security.gentoo.org/glsa/201611-21https://www.exploit-db.com/exploits/39767/https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588https://www.imagemagick.org/script/changelog.phphttp://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLoghttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0726.htmlhttp://www.debian.org/security/2016/dsa-3580http://www.openwall.com/lists/oss-security/2016/05/03/18http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/archive/1/538378/100/0/threadedhttp://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568http://www.ubuntu.com/usn/USN-2990-1https://lists.debian.org/debian-lts-announce/2018/06/msg00009.htmlhttps://security.gentoo.org/glsa/201611-21https://www.exploit-db.com/exploits/39767/https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588https://www.imagemagick.org/script/changelog.php
2016-05-05
Published