CVE-2016-8677: Debian Linux

High severity, CVSS 8.8. EPSS: 3.9% chance of exploitation in the next 30 days.

The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remote attackers to have unspecified impact via a crafted image file, which triggers a memory allocation failure.

Affected products

  • Debian Debian Linux: version 8.0 only
  • ImageMagick ImageMagick: before 6.9.5-10 (fixed in 6.9.5-10); from 7.0.0-0, before 7.0.3-1 (fixed in 7.0.3-1)
  • Opensuse Opensuse: version 13.2 only

Published 2017-02-15. Last modified 2026-06-17.