← לוח פגיעויות

CVE-2016-3714

גבוהה 8.4 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
ImageMagick Improper Input Validation Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

מדדים

CVSS 3.1
8.4 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
97% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-20

מוצרים מושפעים

imagemagick: imagemagick; canonical: ubuntu linux; debian: debian linux; opensuse: leap; opensuse: opensuse; suse: suse linux enterprise server

קישורים