PatchSiren cyber security CVE debrief
CVE-2016-10064 Imagemagick CVE debrief
CVE-2016-10064 is a buffer overflow in ImageMagick’s TIFF handling code (coders/tiff.c). According to the CVE record, a crafted file can cause a denial of service through application crash, and the impact may extend beyond a simple crash. The issue was publicly disclosed on 2017-03-02, and the linked references show patch and advisory activity around the vulnerability.
- Vendor
- Imagemagick
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Organizations running ImageMagick in any workflow that processes untrusted TIFF files should review this immediately, especially web services, document pipelines, media conversion jobs, and distro/package maintainers shipping affected ImageMagick builds.
Technical summary
The CVE description identifies a buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1. NVD maps the issue to CWE-119 and lists vulnerable ImageMagick versions through 6.9.5-0 in the CPE criteria. The stated impact is remote-triggered denial of service via a crafted file, with unspecified additional impact possible. The record also links ImageMagick patch commits and third-party advisories.
Defensive priority
High. The CVSS score is 7.8 (HIGH), and the weakness affects file parsing code that may be exposed to attacker-controlled input.
Recommended defensive actions
- Upgrade ImageMagick to a fixed release at or beyond the version indicated in the CVE description (6.9.5-1 or later).
- Treat any application that accepts user-supplied TIFF content as potentially exposed until patched.
- Verify vendor/package backports if you rely on distro-provided ImageMagick builds; do not assume the package version string alone proves the fix.
- Review adjacent image-processing services for crash monitoring and input validation controls.
- Use the linked vendor and distribution advisories to confirm whether your deployment is covered by a patch or backport.
Evidence notes
Source references include the CVE record, NVD detail, ImageMagick patch commits, a Red Hat bug report, an openSUSE advisory, and an oss-security mailing list post. The narrative description says the issue exists before 6.9.5-1, while NVD CPE criteria mark ImageMagick vulnerable through 6.9.5-0; both are included here as supplied source data. NVD assigns CVSS v3.1 vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H and CWE-119.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10064 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10064
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10064 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10064
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/commit/63302366a63602acbaad5c8223a105811b2adddd
[email protected] - Patch, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/commit/f8877abac8e568b2f339cca70c2c3c1b6eaec288
[email protected] - Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.