PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-8682 Debian CVE debrief

CVE-2016-8682 describes a memory-safety flaw in GraphicsMagick 1.3.25: the ReadSCTImage function in coders/sct.c can read out of bounds when it processes a crafted SCT header. The published impact is denial of service, and NVD rates the issue High with a network attack vector, no privileges, and no user interaction. Public advisories and patch references were circulating in 2016, while the CVE record was published by NVD on 2017-02-15.

Vendor
Debian
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-15
Original CVE updated
2026-05-13
Advisory published
2017-02-15
Advisory updated
2026-05-13

Who should care

Administrators and developers running GraphicsMagick 1.3.25 or downstream packages that include it, especially services that accept untrusted image uploads or convert SCT content.

Technical summary

NVD maps the issue to CWE-125 and the CVSS v3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The flaw is in ReadSCTImage within coders/sct.c, where a crafted SCT header can cause an out-of-bounds read. The documented consequence is remote denial of service, with availability impact only in the NVD record.

Defensive priority

High for any environment that processes untrusted SCT inputs or exposes GraphicsMagick through network-facing services. Because the flaw is remotely triggerable, requires no privileges, and needs no user interaction, patching or vendor package updates should be prioritized.

Recommended defensive actions

  • Inventory all GraphicsMagick deployments and confirm whether version 1.3.25 or a downstream package is present.
  • Apply the upstream or vendor-provided fix referenced by the patch/revision and related distro advisories.
  • Prioritize updates on systems that process attacker-supplied images or expose image-conversion workflows to untrusted input.
  • If immediate patching is not possible, reduce exposure by limiting SCT handling and restricting access to image-processing endpoints.
  • After updating, verify the installed package version against your distribution advisory or upstream patch reference.

Evidence notes

The NVD record states that ReadSCTImage in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause denial of service via a crafted SCT header, and classifies the weakness as CWE-125. The NVD reference set includes an upstream revision/patch, Debian and openSUSE security advisories, an OSS-security mailing list post, a Gentoo advisory, and a Red Hat Bugzilla entry. The affected CPE criteria explicitly include GraphicsMagick 1.3.25, along with downstream Debian and openSUSE package contexts.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-8682 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-8682

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-8682 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8682

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.