CVE-2016-10063

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-10063
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10063.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-10063
Downstream
Related
Published
2017-03-02T21:59:00Z
Modified
2025-10-18T10:51:01.826212Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file, related to extend validity.

References

Affected packages

Git / github.com/imagemagick/imagemagick

Affected ranges

Type
GIT
Repo
https://github.com/imagemagick/imagemagick
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

7.*

7.0.1-0
7.0.1-1
7.0.1-10
7.0.1-2
7.0.1-3
7.0.1-4
7.0.1-5
7.0.1-6
7.0.1-7
7.0.1-8
7.0.1-9
7.0.2-0
7.0.2-1
7.0.2-2

Database specific

vanir_signatures

[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "103697060135959106830542413254913951694",
                "1970232661960226097742482354256480176",
                "140021645161412844653934009265423901104",
                "302084411660785079186154865634642153861",
                "246452775775643479039632313154872888617",
                "96104928818251249225816813371569332163",
                "221605472236257057980001368241814973503",
                "236355740425942618058476961888908248301",
                "92441154995531210210313172415131763886",
                "150240877669528608968858354961175477375"
            ]
        },
        "target": {
            "file": "coders/tiff.c"
        },
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/imagemagick/imagemagick/commit/94936efda8aa63563211eda07a5ade92abb32f7a",
        "signature_version": "v1",
        "id": "CVE-2016-10063-33dd8588"
    },
    {
        "digest": {
            "length": 23155.0,
            "function_hash": "172215250049717264941504509801069341502"
        },
        "target": {
            "function": "ReadTIFFImage",
            "file": "coders/tiff.c"
        },
        "signature_type": "Function",
        "deprecated": false,
        "source": "https://github.com/imagemagick/imagemagick/commit/2bb6941a2d557f26a2f2049ade466e118eeaab91",
        "signature_version": "v1",
        "id": "CVE-2016-10063-76cb0528"
    },
    {
        "digest": {
            "length": 23919.0,
            "function_hash": "237957955268260375240577298103735291751"
        },
        "target": {
            "function": "ReadTIFFImage",
            "file": "coders/tiff.c"
        },
        "signature_type": "Function",
        "deprecated": false,
        "source": "https://github.com/imagemagick/imagemagick/commit/94936efda8aa63563211eda07a5ade92abb32f7a",
        "signature_version": "v1",
        "id": "CVE-2016-10063-9aa5f30e"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "309531415309245492516289000074322004777",
                "158286900341591609423779053651258020838",
                "227606226587041552729349993316568568428",
                "79119237227817969750971569110353603804",
                "195998754719549900261819408483335219650",
                "51589611085731193000899006364071274303",
                "84621561432804615868200120694307231124",
                "72789692611261142092603024766030838246",
                "331403667152163900531105055036556863967",
                "221605472236257057980001368241814973503",
                "236355740425942618058476961888908248301",
                "92441154995531210210313172415131763886",
                "150240877669528608968858354961175477375"
            ]
        },
        "target": {
            "file": "coders/tiff.c"
        },
        "signature_type": "Line",
        "deprecated": false,
        "source": "https://github.com/imagemagick/imagemagick/commit/2bb6941a2d557f26a2f2049ade466e118eeaab91",
        "signature_version": "v1",
        "id": "CVE-2016-10063-e0919938"
    }
]

Git / github.com/imagemagick/imagemagick6

Affected ranges

Type
GIT
Repo
https://github.com/imagemagick/imagemagick6
Events
Introduced
0 Unknown introduced commit / All previous commits are affected