PatchSiren cyber security CVE debrief
CVE-2016-10060 Imagemagick CVE debrief
CVE-2016-10060 is a medium-severity ImageMagick denial-of-service vulnerability in MagickWand/magick-cli.c. When ConcatenateImages processes a crafted file, it fails to check the return value of fputc, which can lead to an application crash. NVD lists affected versions as ImageMagick 6.x before 6.9.4-1 and 7.0.0-0 through 7.0.1-9; the published description also summarizes the issue as affecting versions before 7.0.1-10.
- Vendor
- Imagemagick
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Administrators and developers running ImageMagick in file-processing, upload, thumbnailing, or batch-conversion workflows, especially services that accept untrusted images.
Technical summary
NVD classifies the issue as CWE-252 (unchecked return value). In ConcatenateImages, a write operation via fputc is not verified, so an error path can go unnoticed while processing attacker-controlled input. The result is availability impact only (CVSS 3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).
Defensive priority
Moderate. This is a remotely triggerable, user-interaction-dependent denial-of-service issue; prioritize remediation if ImageMagick is exposed to untrusted files or used in public-facing conversion pipelines.
Recommended defensive actions
- Upgrade ImageMagick to a fixed release in your supported branch; NVD lists the affected ranges as ending before 6.9.4-1 and before 7.0.1-10.
- Verify whether your distribution or vendor package has backported the fix before relying on the upstream version string.
- Restrict and sandbox image-processing workloads that accept untrusted files.
- Monitor for crashes or abnormal termination in image-conversion paths, especially when handling malformed input.
Evidence notes
The vulnerability record in NVD describes an unchecked fputc return value in ConcatenateImages as the root cause and assigns CWE-252. NVD also provides the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, supporting an availability-only impact assessment. References in the record include an oss-security mailing list post, a Red Hat bug entry, an upstream ImageMagick issue, and the upstream commit linked by NVD as the patch reference.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10060 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10060
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10060 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10060
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/commit/933e96f01a8c889c7bf5ffd30020e86a02a046e7
[email protected] - Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/issues/196
[email protected] - Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.