PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-10060 Imagemagick CVE debrief

CVE-2016-10060 is a medium-severity ImageMagick denial-of-service vulnerability in MagickWand/magick-cli.c. When ConcatenateImages processes a crafted file, it fails to check the return value of fputc, which can lead to an application crash. NVD lists affected versions as ImageMagick 6.x before 6.9.4-1 and 7.0.0-0 through 7.0.1-9; the published description also summarizes the issue as affecting versions before 7.0.1-10.

Vendor
Imagemagick
Product
Unknown
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-02
Original CVE updated
2026-05-13
Advisory published
2017-03-02
Advisory updated
2026-05-13

Who should care

Administrators and developers running ImageMagick in file-processing, upload, thumbnailing, or batch-conversion workflows, especially services that accept untrusted images.

Technical summary

NVD classifies the issue as CWE-252 (unchecked return value). In ConcatenateImages, a write operation via fputc is not verified, so an error path can go unnoticed while processing attacker-controlled input. The result is availability impact only (CVSS 3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).

Defensive priority

Moderate. This is a remotely triggerable, user-interaction-dependent denial-of-service issue; prioritize remediation if ImageMagick is exposed to untrusted files or used in public-facing conversion pipelines.

Recommended defensive actions

  • Upgrade ImageMagick to a fixed release in your supported branch; NVD lists the affected ranges as ending before 6.9.4-1 and before 7.0.1-10.
  • Verify whether your distribution or vendor package has backported the fix before relying on the upstream version string.
  • Restrict and sandbox image-processing workloads that accept untrusted files.
  • Monitor for crashes or abnormal termination in image-conversion paths, especially when handling malformed input.

Evidence notes

The vulnerability record in NVD describes an unchecked fputc return value in ConcatenateImages as the root cause and assigns CWE-252. NVD also provides the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, supporting an availability-only impact assessment. References in the record include an oss-security mailing list post, a Red Hat bug entry, an upstream ImageMagick issue, and the upstream commit linked by NVD as the patch reference.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-10060 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-10060

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-10060 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10060

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.