CVE-2016-5688: ImageMagick

High severity, CVSS 8.1. EPSS: 4.8% chance of exploitation in the next 30 days.

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.

Affected products

  • ImageMagick ImageMagick: up to and including 6.9.4-3; version 7.0.1-0 only; version 7.0.1-1 only; version 7.0.1-2 only; version 7.0.1-3 only; version 7.0.1-4 only
  • Oracle Solaris: version 11.3 only

Published 2016-12-13. Last modified 2026-06-17.