PatchSiren cyber security CVE debrief
CVE-2016-10068 Imagemagick CVE debrief
CVE-2016-10068 is a denial-of-service issue in ImageMagick's MSL interpreter affecting versions before 6.9.6-4. A crafted XML file can trigger a segmentation fault and application crash, primarily impacting availability. The NVD entry classifies the weakness as CWE-20 and assigns a Medium CVSS score of 5.5.
- Vendor
- Imagemagick
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Administrators and developers running ImageMagick 6.9.6-3 or earlier, distro/package maintainers, and application teams that process untrusted XML or MSL content through ImageMagick.
Technical summary
The vulnerable component is the MSL interpreter in ImageMagick. According to the supplied record, crafted XML input can cause a segmentation fault and crash. NVD maps the issue to CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating availability-only impact with user interaction required in the scored vector. The weakness is categorized as CWE-20 (improper input validation).
Defensive priority
Medium. This is an availability-impacting crash with a published fix and multiple vendor references. The operational risk is highest where ImageMagick processes untrusted input or is embedded in automated workflows that can be interrupted by a malformed file.
Recommended defensive actions
- Upgrade ImageMagick to 6.9.6-4 or later, or install the vendor/distro package that includes the fix.
- Apply the relevant downstream advisories from your Linux distribution or packaging source.
- Restrict or isolate processing of untrusted XML/MSL content when ImageMagick is used in automated workflows.
- Verify deployed package versions in production systems and rebuild any container images or golden images that still include vulnerable releases.
- Review upstream and vendor references for any environment-specific remediation guidance before re-enabling affected workflows.
Evidence notes
The supplied NVD record lists ImageMagick versions through 6.9.6-3 as vulnerable and links an upstream patch commit (56d6e20de489113617cbbddaf41e92600a34db22), a vendor advisory, mailing-list discussion, and distro advisories. The natural-language description says remote attackers may trigger the issue, while the CVSS vector provided by NVD is AV:L/UI:R; that difference should be kept in mind when assessing real-world exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10068 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10068
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10068 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10068
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/commit/56d6e20de489113617cbbddaf41e92600a34db22
[email protected] - Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.