Junglewise Threat Intelligence

CVE-2016-3714: ImageMagick Improper Input Validation Vulnerability

CVE-2016-3714 · Severity: critical · CVSS 8.4 · Exploited in the wild · Published 2024-09-09

Technologies: ImageMagick. Vendors: ImageMagick.

Executive brief

ImageMagick contains an improper input validation vulnerability, known as 'ImageTragick', affecting multiple coders including EPHEMERAL, HTTPS, and MVG. Remote attackers can execute arbitrary code by using shell metacharacters within a specially crafted image file.

Affected products

  • ImageMagick ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1

Timeline

  • 2016-05-03: disclosed: Public disclosure via oss-security mailing list
  • 2024-09-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-09: other: Advisory publication date

Related threats