CVE-2016-3714

unknown KEV
Published 2024-09-09 ยท Modified 2024-09-09
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
2.5

Description

ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code via shell metacharacters in a crafted image.

CISA KEV

Vendor
ImageMagick
Product
ImageMagick
Due date
2024-09-30

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cisa-kev โ€” This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588#p132726, https://imagemagick.org/archive/releases/; https://nvd.nist.gov/vuln/detail/CVE-2016-3714}

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-39767 dos multiple
Nikolay Ermishkin ยท 2016-05-04

ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities

Source code queued for fetch โ€” refresh in a moment.
EDB-39791 local multiple verified
Metasploit ยท 2016-05-09

ImageMagick 6.9.3-9 / 7.0.1-0 - 'ImageTragick' Delegate Arbitrary Command Execution (Metasploit)

Source code queued for fetch โ€” refresh in a moment.

Metasploit modules

ImageMagick Delegate Arbitrary Command Execution
Source fetch failed: fetch_error โ€” view the original via the link above.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.3.24-1
sid Fixed 1.3.24-1
forky Fixed 1.3.24-1
bullseye Fixed 1.3.24-1
bookworm Fixed 1.3.24-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.