CVE-2016-10060: ImageMagick
Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.
The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
Affected products
- ImageMagick ImageMagick: before 6.9.4-1 (fixed in 6.9.4-1); from 7.0.0-0, before 7.0.1-10 (fixed in 7.0.1-10)
Published 2017-03-02. Last modified 2026-06-17.