← Back

CVE-2016-3718

nvd nist
Published: May 5, 2016Modified: Apr 22, 2026CISA KEV

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

Affected (84)

Show all products
16 products
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Hpc Node
Enterprise Linux Hpc Node Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server From Rhui
Enterprise Linux Server Tus
Enterprise Linux Workstation
1 product
Imagemagick
1 product
Ubuntu Linux
2 products
Linux
Solaris
2 products
Leap
Opensuse
8 products
Linux Enterprise Debuginfo
Linux Enterprise Desktop
Linux Enterprise Server
Manager
Manager Proxy
Openstack Cloud
Configuration A
53 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 7.0
Redhat
Version 6.7
Version 7.2
Version 7.3
Version 7.4
Version 7.5
Version 7.6
Version 7.7
Redhat
Version 6.0_s390x
Version 7.0_s390x
Redhat
Version 6.7_s390x
Version 7.2_s390x
Version 7.3_s390x
Version 7.4_s390x
Version 7.5_s390x
Version 7.6_s390x
Version 7.7_s390x
Redhat
Version 6.0_ppc64
Version 7.0_ppc64
Redhat
Version 6.7_ppc64
Version 7.2_ppc64
Version 7.3_ppc64
Version 7.4_ppc64
Version 7.5_ppc64
Version 7.6_ppc64
Version 7.7_ppc64
Version 7.0_ppc64le
Redhat
Version 7.2_ppc64le
Version 7.3_ppc64le
Version 7.4_ppc64le
Version 7.5_ppc64le
Version 7.6_ppc64le
Version 7.7_ppc64le
Redhat
Version 6.0
Version 7.0
Version 7.2
Redhat
Version 6.0
Version 7.0
Redhat
Version 7.2
Version 7.3
Version 7.4
Version 7.6
Version 7.7
Redhat
Version 6.0
Version 7.0
Version 6.7z
Redhat
Version 7.2
Version 7.3
Version 7.6
Version 7.7
Redhat
Version 6.0
Version 7.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Imagemagick
Before 6.9.3-10
Version 7.0.0-0
Version 7.0.1-0
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 15.10
Version 16.04
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 6
Version 7
Oracle
Version 10
Version 11.3
Configuration E
20 vulnerable

References (39)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.