CVE-2016-3718mediumunder attackCWE-918

CVE-2016-3718

Published · Updated

85Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 5.5epss 77%
from disclosure to weapon0 days
Published on NVDMay 5
1st PoCMay 4
CISA KEV+2008d
exploitation probability
77%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products
Red Hat Enterprise Linux 5 · Red Hat OpenShift Enterprise 2
workaround: Details can be found under the resolve tab at https://access.redhat.com/security/vulnerabilities/2296071 Red Hat Enterprise Linux 6 and 7 ================================ As a workaround the /etc/ImageMagick/policy.xml file can be edited to…
Fixed
14 products (581 components)
Red Hat Enterprise Linux Client (v. 7) · Red Hat Enterprise Linux Client Optional (v. 7) · Red Hat Enterprise Linux ComputeNode Optional (v. 7) · Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server Optional (v. 7) · and others 9
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

ImageMagick can be tricked into making unwanted network requests (HTTP or FTP) when processing a specially crafted image. An attacker could exploit this to access internal systems or services that should not be publicly reachable.

Technical detail

The HTTP and FTP coders in ImageMagick before version 6.9.3-10 and 7.x before 7.0.1-1 are vulnerable to SSRF attacks. An attacker can supply a malicious image file that causes the application to make unintended server-side requests to internal or restricted network resources, potentially bypassing firewall restrictions or accessing sensitive services.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.