Input validation error in ImageMagick - CVE-2016-3714
Published: February 17, 2017 / Updated: September 9, 2024
Vulnerability identifier: #VU5846
CSH Severity: Critical
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3714
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to insufficient filtering for filename passed to delegate's command. A remote attacker can create a specially crafted image containing shell metacharacters, trick the victim into opening it via application using ImageMagick, will trigger an input validation flaw and execute arbitrary shell commands with privileges of the current user.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Note: the vulnerability was being actively exploited.
The weakness exists due to insufficient filtering for filename passed to delegate's command. A remote attacker can create a specially crafted image containing shell metacharacters, trick the victim into opening it via application using ImageMagick, will trigger an input validation flaw and execute arbitrary shell commands with privileges of the current user.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.
Note: the vulnerability was being actively exploited.
Affected software
ImageMagick
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
Opensuse
imagemagick (Alpine package)
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
Opensuse
imagemagick (Alpine package)
How to mitigate CVE-2016-3714
Update to version 6.9.3-10 or 7.0.1-1.
imagemagick (Alpine package) - update to 6.9.3.10-r0
Links to Public Exploits and PoC-codes
- Exploit #7942 - pandagik (Image Magick Exploit for CVE-2016–3714) (June 1, 2022)
- Exploit #1043 - ImageMagick 6.9.3-9 / 7.0.1-0 - Delegate Arbitrary Command Execution (ImageTragick) (Metasploit) (March 18, 2020)
- Exploit #1044 - ImageMagick 6.9.3-9 / 7.0.1-0 - Multiple Vulnerabilities (ImageTragick) (March 18, 2020)
- Exploit #1741 - ImageMagick Delegate Arbitrary Command Execution (March 18, 2020)
External References
Related Security Bulletins
- Remote code execution in ImageMagick
- Arch Linux update for imagemagick
- SUSE Linux update for ImageMagick
- OpenSUSE Linux update for GraphicsMagick
- SUSE Linux update for ImageMagick
- OpenSUSE Linux update for ImageMagick
- SUSE Linux update for ImageMagick
- Input validation error in imagemagick (Alpine package)
- Amazon Linux AMI update for ImageMagick
- Gentoo update for ImageMagick
- Slackware Linux update for imagemagick