CVE-2016-10061: ImageMagick

Medium severity, CVSS 6.5. EPSS: 2.9% chance of exploitation in the next 30 days.

The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.

Affected products

  • ImageMagick ImageMagick: before 6.9.4-8 (fixed in 6.9.4-8); from 7.0.0-0, before 7.0.1-10 (fixed in 7.0.1-10)

Published 2017-03-03. Last modified 2026-06-17.