Facebook paid Russian security researcher Andrey Leonov $40,000 after he reported that an image-conversion service used a vulnerable version of ImageMagick. SecurityWeek reported the payout on January 18, 2017, attributing its confirmation to Facebook. The report described a vulnerability finding and responsible disclosure—not a confirmed breach.
What happened in Facebook’s image-conversion flow
As SecurityWeek described it, Facebook’s service accepted a URL through a picture parameter, fetched the image, converted it, and then displayed it. Leonov reportedly found that the URL-fetching request did not respond to the tests he tried; the vulnerable component was the ImageMagick converter used afterward.
Leonov reported the issue on October 16, 2016. SecurityWeek said Facebook patched it three days later and called the $40,000 award Facebook’s largest bounty to that date. Those payout and remediation details come from SecurityWeek’s January 18, 2017 report, which said Facebook confirmed the award; they should not be read as independently published Facebook announcement details. The report gave no indication the flaw had been exploited before patching, and Leonov reportedly avoided deeper exploitation to respect responsible disclosure.
What ImageTragick was—and why an image could be dangerous
ImageTragick is the name commonly associated with CVE-2016-3714 and a related group of ImageMagick security issues disclosed in 2016. The core risk was that crafted image input could reach ImageMagick coders or delegate programs in ways that allowed unintended actions. NIST’s CVE record describes remote code execution through shell metacharacters in a crafted image; depending on the vulnerable processing path, an attacker could run commands with the privileges of the process handling that image.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
The disclosure covered more than one possible impact, including file access or manipulation through image coders and pseudo-protocols. That matters to services accepting uploads or processing images fetched from elsewhere: the file’s apparent type does not make its decoding harmless. A service may pass it through complex parsers and external helpers as part of conversion.
How the vulnerability was disclosed
- April 21, 2016: The disclosure timeline says an initial file-read report involving a My.Com service reached the Mail.Ru Security Team; the service team patched it that day.
- April 28: Nikolay Ermishkin found code execution while investigating the earlier report.
- April 30: The issue was reported to ImageMagick. An initial fix and release 6.9.3-9 followed, but the disclosure project says the fix was incomplete.
- May 1–3: A bypass was reported, distribution maintainers received limited disclosure, and public disclosure followed on May 3.
- October 16–19: Leonov reportedly reported Facebook’s converter issue on October 16; SecurityWeek said it was patched three days later.
- January 18, 2017: SecurityWeek published its account of the Facebook bounty.
Was Facebook vulnerable to CVE-2016-3714?
The reported Facebook finding involved a vulnerable ImageMagick version in an image-conversion flow, but the report does not identify the exact installed version or establish that Facebook’s issue was specifically exploited through CVE-2016-3714. “ImageTragick” is used in the report’s framing, while CVE-2016-3714 is one named vulnerability within the 2016 disclosure context. The available account supports saying that a vulnerable ImageMagick converter was found and patched—not that a breach occurred or that every detail of the CVE path was demonstrated on Facebook.
NIST’s upstream CVE record lists versions earlier than ImageMagick 6.9.3-10 and ImageMagick 7.0.1-1 as affected by CVE-2016-3714. Those upstream thresholds do not, by themselves, determine whether a particular operating-system package is vulnerable: distributions may backport fixes while retaining an older-looking version number. For an installed system, use the distribution or vendor advisory and its package status.
What the incident teaches about securing image processing
The key architectural lesson is to treat fetching and conversion as separate security boundaries. A URL fetcher can be safe against the tests applied to it while the subsequent converter remains vulnerable. Security controls therefore need to cover the image-processing stage itself, including the libraries and delegate programs it invokes.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
- Validate inputs: The ImageTragick disclosure recommended checking that a file begins with the expected signature bytes for a supported image type before passing it to ImageMagick. A signature check is a useful gate, not proof that all later processing is safe.
- Restrict processing capabilities: The disclosure recommended disabling vulnerable coders through ImageMagick policy configuration. Such controls should be paired with a deliberate decision about which formats a service actually needs.
- Use vendor-maintained fixes: Apply current security updates for the relevant operating system or ImageMagick package. Do not treat old upstream version boundaries or a 2016 workaround as current deployment guidance.
- Limit consequences: Since commands run by a vulnerable processing path may inherit the converter process’s privileges, the service should avoid granting that process unnecessary access. The incident materials establish the privilege-dependent risk, though they do not prescribe a universal isolation design.
What the 2016 Ubuntu fix illustrates
Ubuntu Security Notice USN-2990-1, published June 2, 2016, said its update disabled problematic coders through /etc/ImageMagick-6/policy.xml and listed corrected package versions for Ubuntu 12.04, 14.04, 15.10, and 16.04. For Ubuntu 16.04, the listed fixed package was 8:6.8.9.9-7ubuntu5.1. This is historical package information, not a current version recommendation.
Ubuntu cautioned that some environments might need to re-enable coders manually, and only after ensuring ImageMagick would not process untrusted input. The notice stated that “a standard system update will make all the necessary changes” in general; administrators should still consult the advisory for the specific release and package they run.
Quick Recap
Best Value
Rank #4
Sources
- SecurityWeek: Facebook Awards $40,000 Bounty for ImageTragick Hack (January 18, 2017).
- NIST National Vulnerability Database: CVE-2016-3714.
- ImageTragick disclosure project: ImageMagick Is On Fire — CVE-2016-3714.
- Canonical / Ubuntu Security Notice USN-2990-1 (June 2, 2016).
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

