CyberICT

CVE-2016-3714

ImageMagick · Published May 5, 2016

CVSS v3.1

HIGH
Patch availableGet patch

Description

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

Affected Products

  • Imagemagick <= 6.9.3-9
  • Imagemagick
  • Ubuntu Linux
  • Debian Linux

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H