The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-484-1 | graphicsmagick security update |
![]() |
DLA-486-1 | imagemagick security update |
![]() |
DLA-1401-1 | graphicsmagick security update |
![]() |
DSA-3580-1 | imagemagick security update |
![]() |
USN-2990-1 | ImageMagick vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Feb 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|
Wed, 14 Aug 2024 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-07-30T01:46:38.273Z
Reserved: 2016-03-30T00:00:00.000Z
Link: CVE-2016-3718

Updated: 2024-08-06T00:03:34.460Z

Status : Deferred
Published: 2016-05-05T18:59:08.960
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-3718


No data.