5.5

CVE-2016-3718

Warnung
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Version 7.6
Redhat ≫ Enterprise Linux Eus Version 7.7
Imagemagick ≫ Imagemagick Version < 6.9.3-10
Imagemagick ≫ Imagemagick Version 7.0.0-0
Imagemagick ≫ Imagemagick Version 7.0.1-0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.10
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Oracle ≫ Linux Version 6 Update -
Oracle ≫ Linux Version 7 Update -
Oracle ≫ Solaris Version 10
Oracle ≫ Solaris Version 11.3
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp2
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp3
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Manager Version 2.1
Suse ≫ Manager Proxy Version 2.1
Suse ≫ Openstack Cloud Version 5
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Opensuse Version 13.2
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Server Version 12 Update sp1
Suse ≫ Linux Enterprise Workstation Extension Version 12 Update sp1

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

Schwachstelle

ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 76.9% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
Third Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
Third Party Advisory
http://git.imagemagick.org/repos/ImageMagick/blob/a01518e08c840577cabd7d3ff291a9ba735f7276/ChangeLog
Patch
Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00024.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00025.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00028.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00032.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00051.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0726.html
Third Party Advisory
http://www.debian.org/security/2016/dsa-3580
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2016/05/03/18
Third Party Advisory
Mailing List
http://www.securityfocus.com/archive/1/538378/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.440568
Third Party Advisory
http://www.ubuntu.com/usn/USN-2990-1
Third Party Advisory
https://security.gentoo.org/glsa/201611-21
Third Party Advisory
https://www.exploit-db.com/exploits/39767/
Third Party Advisory
VDB Entry
https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588
Vendor Advisory
https://www.imagemagick.org/script/changelog.php
Release Notes
https://lists.debian.org/debian-lts-announce/2018/06/msg00009.html
Third Party Advisory
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3718
US Government Resource