PatchSiren cyber security CVE debrief
CVE-2016-10066 Imagemagick CVE debrief
CVE-2016-10066 is a denial-of-service flaw in ImageMagick’s VIFF image parser. A crafted file can trigger a buffer overflow in ReadVIFFImage, causing the application to crash. The issue affects ImageMagick versions before 6.9.4-5 and is most relevant anywhere untrusted image uploads or conversions are accepted.
- Vendor
- Imagemagick
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-03
- Advisory updated
- 2026-05-13
Who should care
Operators and developers who use ImageMagick to process user-supplied images, especially web services, document pipelines, thumbnailers, and content ingestion systems that may accept VIFF files.
Technical summary
NVD describes a buffer overflow in coders/viff.c:ReadVIFFImage in ImageMagick before 6.9.4-5. The vulnerable condition is reachable through a crafted file and is classified by NVD with CWE-120. The NVD CVSS vector (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) indicates an availability impact with user interaction required, so the practical risk is highest where the application opens attacker-controlled files during normal workflows.
Defensive priority
Medium
Recommended defensive actions
- Upgrade ImageMagick to 6.9.4-5 or later, or the vendor-fixed version in your distribution.
- If VIFF support is not needed, remove or disable processing of VIFF files in exposed workflows.
- Treat all image uploads and conversions as untrusted input and isolate ImageMagick in least-privilege, sandboxed, or containerized execution.
- Add monitoring for unexpected crashes in image-processing services and review any file-type allowlists that may permit VIFF.
- Verify downstream packages and bundled copies of ImageMagick, since vulnerable versions may be embedded in applications or platform images.
Evidence notes
The vulnerability and version cutoff come from the NVD record for CVE-2016-10066, which lists the affected CPE range as ImageMagick through 6.9.4-4 and cites CWE-120. The record references an oss-security mailing list disclosure from 2016-12-26, a Red Hat bug tracker entry, and ImageMagick GitHub commits associated with the fix. The CVE was published on 2017-03-03; the later modified date reflects database updates, not a new issue date.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10066 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10066
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10066 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10066
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/commit/e45e48b881038487d0bc94d92a16c1537616cc0a
[email protected] - Patch, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/commit/f6e9d0d9955e85bdd7540b251cd50d598dacc5e6
[email protected] - Issue Tracking, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.