CVE-2016-3714

unknown KEV
Published 2024-09-09 · Modified 2024-09-09
CVSS v3
CVSS v2
VIR risk
1.5

Description

ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code via shell metacharacters in a crafted image.

CISA KEV

Vendor
ImageMagick
Product
ImageMagick
Due date
2024-09-30

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588#p132726, https://imagemagick.org/archive/releases/; https://nvd.nist.gov/vuln/detail/CVE-2016-3714

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-3714

Exploits

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.3.24-1
debian debianbullseyefixed1.3.24-1
debian debianforkyfixed1.3.24-1
debian debiansidfixed1.3.24-1
debian debiantrixiefixed1.3.24-1

References

Verify integrity in audit chain (admin only). AS-IS.