⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2022-05-03. Required action: Apply updates per vendor instructions..
Severity
5.5MEDIUM
EPSS
83.8%
top 0.71%
CISA KEV
KEV
Added 2021-11-03
Due 2022-05-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMay 5
KEV addedNov 3
KEV dueMay 3
Latest updateMay 14
CISA Required Action: Apply updates per vendor instructions.

Description

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages19 packages

NVDimagemagick/imagemagick< 6.9.3-10+2
Debianimagemagick< 8:6.9.6.2+dfsg-2+3
Debiangraphicsmagick< 1.3.24-1+3

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04, Enterprise Linux 6.7, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 6.0, 7.0, 6.0_ppc64, 7.0_ppc64, 6.7_ppc64, 7.2_ppc64, 7.3_ppc64, 7.4_ppc64, 7.5_ppc64, 7.6_ppc64, 7.7_ppc64, 6.7z

Patches

🔴Vulnerability Details

5
GHSA
GHSA-q994-gg9f-3g56: The (1) HTTP and (2) FTP coders in ImageMagick before 62022-05-14
OSV
imagemagick vulnerabilities2016-06-02
CVEList
CVE-2016-3718: The (1) HTTP and (2) FTP coders in ImageMagick before 62016-05-05
OSV
CVE-2016-3718: The (1) HTTP and (2) FTP coders in ImageMagick before 62016-05-05
VulnCheck
ImageMagick Server-Side Request Forgery (SSRF) Vulnerability2016

💥Exploits & PoCs

1
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities2016-05-04

🔍Detection Rules

1
Suricata
ET WEB_SERVER ImageMagick CVE-2016-3718 SSRF Inbound (mvg + fill + url)2016-05-04

📋Vendor Advisories

4
CISA
ImageMagick Server-Side Request Forgery (SSRF) Vulnerability2021-11-03
Ubuntu
ImageMagick vulnerabilities2016-06-02
Red Hat
ImageMagick: SSRF vulnerability2016-05-03
Debian
CVE-2016-3718: graphicsmagick - The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7....2016

💬Community

2
Bugzilla
CVE-2016-3718 ImageMagick: SSRF vulnerability [fedora-all]2016-05-04
Bugzilla
CVE-2016-3718 ImageMagick: SSRF vulnerability2016-05-04