CVE-2016-6823: ImageMagick

High severity, CVSS 7.5. EPSS: 4.8% chance of exploitation in the next 30 days.

Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.

Affected products

  • ImageMagick ImageMagick: before 6.9.10-50 (fixed in 6.9.10-50); from 7.0.0-0, before 7.0.2-10 (fixed in 7.0.2-10)

Published 2017-01-18. Last modified 2026-06-17.