ZeroHour

CVE-2016-3718

KEVmass

Server-Side Request Forgery in ImageMagick HTTP/FTP Coders

CISA: ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

CVSS 3.1
5.5 medium
EPSS
77%p100
Published
()
KEV added
AI analysis

CVE-2016-3718 is a server-side request forgery (SSRF) flaw, CWE-918, in the HTTP and FTP coders of ImageMagick, disclosed in 2016 as part of the 'ImageTragick' family of vulnerabilities. It is triggered when ImageMagick processes an image whose filename or reference uses an http:// or ftp:// URL, for example when a web application passes user-supplied images or URLs to the ImageMagick command-line tools or API, causing the library to fetch the attacker-controlled URL from the server. An attacker gains the ability to make the vulnerable server issue requests to attacker-chosen internal or external targets (such as internal-only services or cloud metadata endpoints), yielding network reconnaissance and information disclosure, though not the full code execution offered by the related ImageTragick RCE, CVE-2016-3714. Any system running ImageMagick before 6.9.3-10 or 7.x before 7.0.1-1 is affected, including builds shipped in Red Hat Enterprise Linux channels and, per the vendor data, distributions from Canonical, Oracle, SUSE, and openSUSE. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), so exploitation is known in the wild, and its EPSS score of about 77% (100th percentile) indicates a very high likelihood of exploitation activity.

What to do: Upgrade ImageMagick to 6.9.3-10 or later (6.x) or 7.0.1-1 or later (7.x), or apply the backported patches from your distribution (Red Hat, Canonical, SUSE, Oracle). As an interim mitigation, restrict or disable the HTTP and FTP coders via ImageMagick's policy.xml and validate that user-supplied image paths and URLs cannot contain http:// or ftp:// references. Prioritize patching applications that feed untrusted images or URLs to ImageMagick, such as upload processors and web image pipelines.

Affected
ImageMagickbefore 6.9.3-10 and 7.x before 7.0.1-1
redhat Enterprise Linux Desktop (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux EUS (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux for IBM z Systems (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux for IBM z Systems EUS (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux for Power Big Endian (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux for Power Big Endian EUS (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux for Power Little Endian (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux for Power Little Endian EUS (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux HPC Node (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux HPC Node EUS (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
redhat Enterprise Linux Server (ImageMagick)before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped)
Estimated exposure
massmillions of Linux servers and web hosts (ImageMagick is bundled by default across major distributions and web stacks) — ImageMagick ships with virtually every major Linux distribution (RHEL, Ubuntu, SUSE, Oracle, openSUSE) and is a standard dependency of web hosting and image-processing stacks, implying an install base in the millions, though practical SSRF…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

CISA Known Exploited Vulnerability
Affected
ImageMagick ImageMagick
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
redhatimagemagickcanonicaloraclesuseopensuse
Products
enterprise linux desktop, enterprise linux eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power big endian, enterprise linux for power big endian eus, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus
Weakness
CWE-918
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.