CVE-2016-3718
KEVmassServer-Side Request Forgery in ImageMagick HTTP/FTP Coders
CISA: ImageMagick Server-Side Request Forgery (SSRF) Vulnerability
CVE-2016-3718 is a server-side request forgery (SSRF) flaw, CWE-918, in the HTTP and FTP coders of ImageMagick, disclosed in 2016 as part of the 'ImageTragick' family of vulnerabilities. It is triggered when ImageMagick processes an image whose filename or reference uses an http:// or ftp:// URL, for example when a web application passes user-supplied images or URLs to the ImageMagick command-line tools or API, causing the library to fetch the attacker-controlled URL from the server. An attacker gains the ability to make the vulnerable server issue requests to attacker-chosen internal or external targets (such as internal-only services or cloud metadata endpoints), yielding network reconnaissance and information disclosure, though not the full code execution offered by the related ImageTragick RCE, CVE-2016-3714. Any system running ImageMagick before 6.9.3-10 or 7.x before 7.0.1-1 is affected, including builds shipped in Red Hat Enterprise Linux channels and, per the vendor data, distributions from Canonical, Oracle, SUSE, and openSUSE. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), so exploitation is known in the wild, and its EPSS score of about 77% (100th percentile) indicates a very high likelihood of exploitation activity.
What to do: Upgrade ImageMagick to 6.9.3-10 or later (6.x) or 7.0.1-1 or later (7.x), or apply the backported patches from your distribution (Red Hat, Canonical, SUSE, Oracle). As an interim mitigation, restrict or disable the HTTP and FTP coders via ImageMagick's policy.xml and validate that user-supplied image paths and URLs cannot contain http:// or ftp:// references. Prioritize patching applications that feed untrusted images or URLs to ImageMagick, such as upload processors and web image pipelines.
| ImageMagick | before 6.9.3-10 and 7.x before 7.0.1-1 |
| redhat Enterprise Linux Desktop (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux EUS (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux for IBM z Systems (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux for IBM z Systems EUS (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux for Power Big Endian (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux for Power Big Endian EUS (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux for Power Little Endian (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux for Power Little Endian EUS (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux HPC Node (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux HPC Node EUS (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
| redhat Enterprise Linux Server (ImageMagick) | before 6.9.3-10 and 7.x before 7.0.1-1 (as shipped) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
- Affected
- ImageMagick ImageMagick
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- redhatimagemagickcanonicaloraclesuseopensuse
- Products
- enterprise linux desktop, enterprise linux eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for power big endian, enterprise linux for power big endian eus, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.