CVE-2016-3714
גבוהה 8.4 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- ImageMagick Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
מדדים
- CVSS 3.1
-
8.4 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 97% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-20
מוצרים מושפעים
imagemagick: imagemagick; canonical: ubuntu linux; debian: debian linux; opensuse: leap; opensuse: opensuse; suse: suse linux enterprise server
קישורים
- https://imagetragick.com/ Vendor Advisory
- https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588 Vendor Advisory
- https://www.imagemagick.org/script/changelog.php Vendor Advisory
- https://imagetragick.com/ Vendor Advisory
- https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588 Vendor Advisory
- https://www.imagemagick.org/script/changelog.php Vendor Advisory
- http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291… Patch
- http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291… Patch
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.html Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.html Third Party Advisory