CVE-2016-3718
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
- Redhat Enterprise Linux Desktop
- = 6.0, 7.0
- Redhat Enterprise Linux Eus
- = 6.7, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7
- Redhat Enterprise Linux For Ibm Z Systems
- = 6.0_s390x, 7.0_s390x
- Redhat Enterprise Linux For Ibm Z Systems Eus
- = 6.7_s390x, 7.2_s390x, 7.3_s390x, 7.4_s390x, 7.5_s390x, 7.6_s390x, 7.7_s390x
- Redhat Enterprise Linux For Power Big Endian
- = 6.0_ppc64, 7.0_ppc64
- Redhat Enterprise Linux For Power Big Endian Eus
- = 6.7_ppc64, 7.2_ppc64, 7.3_ppc64, 7.4_ppc64, 7.5_ppc64, 7.6_ppc64, 7.7_ppc64
- Fix
- Available
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 76.9% (100th percentile)
- Weakness
- CWE-918
- NVD status
- Analyzed
- Published
- 2016-05-05
CVE-2016-3718 at NVD
4 known exploits for CVE-2016-3718
Proof-of-concept code and exploit modules indexed by Sploitus