CVE-2016-3718
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Affected (84)
Products: Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Big Endian Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux Hpc Node, Enterprise Linux Hpc Node Eus, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server From Rhui, Enterprise Linux Server Supplementary Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation · Imagemagick: Imagemagick · Canonical: Ubuntu Linux · +3 more
Show all products
Redhat: Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Big Endian Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux Hpc Node, Enterprise Linux Hpc Node Eus, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server From Rhui, Enterprise Linux Server Supplementary Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation · Imagemagick: Imagemagick · Canonical: Ubuntu Linux · Oracle: Linux, Solaris · Opensuse: Leap, Opensuse · Suse: Linux Enterprise Debuginfo, Linux Enterprise Desktop, Linux Enterprise Server, Linux Enterprise Software Development Kit, Linux Enterprise Workstation Extension, Manager, Manager Proxy, Openstack Cloud
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.7 | |
| Version 6.0_s390x | |
| Version 6.7_s390x | |
| Version 6.0_ppc64 | |
| Version 6.7_ppc64 | |
| Version 7.0_ppc64le | |
| Version 7.2_ppc64le | |
| Version 6.0 | |
| Version 7.2 | |
| Version 6.0 | |
| Version 7.2 | |
| Version 6.0 | |
| Version 6.7z | |
| Version 7.2 | |
| Version 6.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.9.3-10 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.04 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 42.1 | |
| Version 13.2 | |
| Version 11 sp2 | |
| Version 12 | |
| Version 11 sp2 | |
| Version 11 sp4 | |
| Version 12 | |
| Version 2.1 | |
| Version 2.1 | |
| Version 5 |
References (39)
http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLog
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Broken LinkThird Party AdvisoryVDB Entry
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Vendor Advisory
http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLog
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.