CVE-2016-3718
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
ImageMagick can be tricked into making unwanted network requests (HTTP or FTP) when processing a specially crafted image. An attacker could exploit this to access internal systems or services that should not be publicly reachable.
The HTTP and FTP coders in ImageMagick before version 6.9.3-10 and 7.x before 7.0.1-1 are vulnerable to SSRF attacks. An attacker can supply a malicious image file that causes the application to make unintended server-side requests to internal or restricted network resources, potentially bypassing firewall restrictions or accessing sensitive services.
The full analysis of this CVE is available in Portuguese →