CVE-2016-3714

Description

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka ImageTragick.

Risk Information

Base Score
8.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
93.749

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.1Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.1Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.1Windows
Image manipulation programs and library (USN-2990-1) imagemagick_6.6.9.7-5ubuntu3.4_i386.debLinux
Image manipulation programs and library (USN-2990-1) imagemagick_6.6.9.7-5ubuntu3.4_amd64.debLinux
Image manipulation programs and library (USN-2990-1) imagemagick_6.8.9.9-5ubuntu2.1_i386.debLinux
Image manipulation programs and library (USN-2990-1) imagemagick_6.8.9.9-5ubuntu2.1_amd64.debLinux
Image manipulation programs and library (USN-2990-1) imagemagick_6.8.9.9-7ubuntu5.1_i386.debLinux
Image manipulation programs and library (USN-2990-1) imagemagick_6.8.9.9-7ubuntu5.1_amd64.debLinux
Image manipulation programs and library (USN-2990-1) imagemagick_6.7.7.10-6ubuntu3.1_i386.debLinux
Image manipulation programs and library (USN-2990-1) imagemagick_6.7.7.10-6ubuntu3.1_amd64.debLinux
Image manipulation programs and library (USN-2990-1) libmagick++4_6.6.9.7-5ubuntu3.4_i386.debLinux
Image manipulation programs and library (USN-2990-1) libmagick++4_6.6.9.7-5ubuntu3.4_amd64.debLinux
Image manipulation programs and library (USN-2990-1) libmagick++5_6.7.7.10-6ubuntu3.1_i386.debLinux
Image manipulation programs and library (USN-2990-1) libmagick++5_6.7.7.10-6ubuntu3.1_amd64.debLinux
Image manipulation programs and library (USN-2990-1) libmagickcore4_6.6.9.7-5ubuntu3.4_i386.debLinux
Image manipulation programs and library (USN-2990-1) libmagickcore4_6.6.9.7-5ubuntu3.4_amd64.debLinux
Image manipulation programs and library (USN-2990-1) libmagickcore5_6.7.7.10-6ubuntu3.1_i386.debLinux
Image manipulation programs and library (USN-2990-1) libmagickcore5_6.7.7.10-6ubuntu3.1_amd64.debLinux
Image manipulation programs and library (USN-2990-1) libmagick++-6.q16-5v5_6.8.9.9-7ubuntu5_i386.debLinux
Image manipulation programs and library (USN-2990-1) libmagick++-6.q16-5v5_6.8.9.9-7ubuntu5.1_i386.debLinux
Image manipulation programs and library (USN-2990-1) libmagick++-6.q16-5v5_6.8.9.9-7ubuntu5.1_amd64.debLinux
Image manipulation programs and library (USN-2990-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5_i386.debLinux
Image manipulation programs and library (USN-2990-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.1_i386.debLinux
Image manipulation programs and library (USN-2990-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.1_amd64.debLinux
graphicsmagick security update(DSA-3746-1) graphicsmagick_1.3.20-3+deb8u2_kfreebsd-i386.debLinux
graphicsmagick security update(DSA-3746-1) graphicsmagick_1.3.20-3+deb8u2_kfreebsd-amd64.debLinux
Improper Input Validation Vulnerability (CVE-2016-3714)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234