CVE-2016-3718 Details
Description
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
A server-side request forgery (SSRF) vulnerability has been identified in ImageMagick versions prior to 6.9.3-10 and in the 7.x branch prior to 7.0.1-1. This vulnerability allows remote attackers to manipulate the server into making HTTP GET or FTP requests to external servers, potentially leading to unauthorized access or information disclosure.
Users can upgrade to ImageMagick versions 6.9.3-10 or 7.0.1-1 or later. For users of Red Hat Enterprise Linux, the update is available through the Red Hat Update System. openSUSE users can upgrade via the openSUSE Security Update mechanism. Instructions for other distributions can be found in the respective security advisories.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| ImageMagick Server-Side Request Forgery (SSRF) Vulnerability | Nov 3, 2021 | May 3, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| redhat enterprise linux desktop | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 6.7 7.2 7.3 7.4 7.5 7.6 7.7 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems | 6.0_s390x 7.0_s390x |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems eus | 6.7_s390x 7.2_s390x 7.3_s390x 7.4_s390x 7.5_s390x 7.6_s390x 7.7_s390x |
CPE
Remediation
| |
| redhat enterprise linux for power big endian | 6.0_ppc64 7.0_ppc64 |
CPE
Remediation
| |
| redhat enterprise linux for power big endian eus | 6.7_ppc64 7.2_ppc64 7.3_ppc64 7.4_ppc64 7.5_ppc64 7.6_ppc64 7.7_ppc64 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian | 7.0_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux for power little endian eus | 7.2_ppc64le 7.3_ppc64le 7.4_ppc64le 7.5_ppc64le 7.6_ppc64le 7.7_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux hpc node | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux hpc node eus | 7.2 |
CPE
Remediation
| |
| redhat enterprise linux server | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux server aus | 7.2 7.3 7.4 7.6 7.7 |
CPE
Remediation
| |
| redhat enterprise linux server from rhui | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux server supplementary eus | 6.7z |
CPE
Remediation
| |
| redhat enterprise linux server tus | 7.2 7.3 7.6 7.7 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 6.0 7.0 |
CPE
Remediation
| |
| imagemagick imagemagick | < 6.9.3-10 7.0.0-0 7.0.1-0 |
CPE
Remediation
| |
| canonical ubuntu linux | 12.04 14.04 15.10 16.04 |
CPE
Remediation
| |
| oracle linux | 6 - 7 - |
CPE
Remediation
| |
| oracle solaris | 10 11.3 |
CPE
Remediation
| |
| suse linux enterprise debuginfo | 11 sp2 11 sp3 11 sp4 |
CPE
Remediation
| |
| suse manager | 2.1 |
CPE
Remediation
| |
| suse manager proxy | 2.1 |
CPE
Remediation
| |
| suse openstack cloud | 5 |
CPE
Remediation
| |
| opensuse leap | 42.1 |
CPE
Remediation
| |
| opensuse opensuse | 13.2 |
CPE
Remediation
| |
| suse linux enterprise desktop | 12 - 12 sp1 |
CPE
Remediation
| |
| suse linux enterprise server | 11 sp2 11 sp3 11 sp4 12 - 12 sp1 |
CPE
Remediation
| |
| suse linux enterprise software development kit | 11 sp4 12 - 12 sp1 |
CPE
Remediation
| |
| suse linux enterprise workstation extension | 12 - 12 sp1 |
CPE
Remediation
| |
Change History
27 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Apr 2, 2025 | Modified Analysis | [email protected] |
| Feb 7, 2025 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 24, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 12, 2023 | CVE Modified | [email protected] |
| Feb 2, 2023 | CVE Modified | [email protected] |
| Oct 9, 2018 | CVE Modified | [email protected] |
| Jun 29, 2018 | CVE Modified | [email protected] |
| Sep 7, 2017 | CVE Modified | [email protected] |
| Jul 1, 2017 | CVE Modified | [email protected] |
| Dec 1, 2016 | CVE Modified | [email protected] |
| Oct 4, 2016 | CVE Modified | [email protected] |
| Sep 23, 2016 | CVE Modified | [email protected] |
| Aug 22, 2016 | Modified Analysis | [email protected] |
| Jul 14, 2016 | CVE Modified | [email protected] |
| Jun 21, 2016 | Modified Analysis | [email protected] |
| Jun 21, 2016 | CVE Modified | [email protected] |
| May 9, 2016 | Modified Analysis | [email protected] |
| May 6, 2016 | Initial Analysis | [email protected] |