CVE-2016-3714
KEVmassCommand Injection RCE in ImageMagick Image Coders (ImageTragick)
CISA: ImageMagick Improper Input Validation Vulnerability
ImageTragick (CVE-2016-3714) is an improper input validation flaw in ImageMagick's EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders that allows shell metacharacters embedded in a crafted image to be passed to the command shell. It is triggered whenever ImageMagick processes a malicious image file — typically when a web application converts or thumbnails user-supplied uploads or URLs. A successful attacker gains arbitrary command and code execution on the host running ImageMagick, with the privileges of that process. Anyone running affected versions of ImageMagick — before 6.9.3-10 in the 6.x line or before 7.0.1-1 in the 7.x line, including builds shipped with Ubuntu, Debian, openSUSE/Leap and SUSE Linux Enterprise Server — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09, and EPSS places its 30-day exploitation probability at 97.5% (100th percentile), consistent with active exploitation.
What to do: Upgrade ImageMagick to 6.9.3-10 or later (6.x) or 7.0.1-1 or later (7.x), or apply the security updates issued by Ubuntu, Debian, openSUSE and SUSE. As an interim mitigation, disable or restrict the vulnerable coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT) via ImageMagick's policy.xml and avoid passing user-controlled filenames or URLs unfiltered to ImageMagick. Prioritize auditing internet-facing services that process user-uploaded images (CMSs, forums, image pipelines), which are the typical delivery path for this flaw.
| ImageMagick (6.x line) | before 6.9.3-10 |
| ImageMagick (7.x line) | 7.x before 7.0.1-1 |
| Canonical Ubuntu Linux | — |
| Debian Linux | — |
| openSUSE / openSUSE Leap | — |
| SUSE Linux Enterprise Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
- Affected
- ImageMagick ImageMagick
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- imagemagickcanonicaldebianopensusesuse
- Products
- imagemagick, ubuntu linux, debian linux, leap, opensuse, suse linux enterprise server
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H