{"id":"CVE-2016-10050","details":"Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.","modified":"2026-04-11T03:36:50.013367Z","published":"2017-03-23T17:59:00.437Z","related":["SUSE-SU-2017:0518-1","SUSE-SU-2017:0529-1","SUSE-SU-2017:0586-1","SUSE-SU-2017:1599-1"],"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/12/26/9"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95185"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2017-02/msg00028.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2017-02/msg00031.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1410454"},{"type":"FIX","url":"https://github.com/ImageMagick/ImageMagick/commit/139d4323c40d7363bfdd2382c3821a6f76d69430"},{"type":"FIX","url":"https://github.com/ImageMagick/ImageMagick/commit/73fb0aac5b958521e1511e179ecc0ad49f70ebaf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/imagemagick/imagemagick","events":[{"introduced":"0"},{"fixed":"139d4323c40d7363bfdd2382c3821a6f76d69430"},{"fixed":"73fb0aac5b958521e1511e179ecc0ad49f70ebaf"}]},{"type":"GIT","repo":"https://github.com/imagemagick/imagemagick6","events":[{"introduced":"0"},{"last_affected":"ac897074952c9d61f60435032a02cdc9742c4c5d"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"6.9.4-8"}]}}],"versions":["6.9.4-0","6.9.4-1","6.9.4-2","6.9.4-3","6.9.4-4","6.9.4-5","6.9.4-6","6.9.4-7","6.9.4-8","7.0.1-0","7.0.1-1","7.0.1-2","7.0.1-3","7.0.1-4","7.0.1-5","7.0.1-6","7.0.1-7","7.0.1-8","7.0.1-9"],"database_specific":{"vanir_signatures":[{"id":"CVE-2016-10050-5f01c242","target":{"file":"coders/rle.c","function":"ReadRLEImage"},"digest":{"length":10838,"function_hash":"77626898924781479573835170477845610344"},"deprecated":false,"signature_version":"v1","signature_type":"Function","source":"https://github.com/imagemagick/imagemagick/commit/139d4323c40d7363bfdd2382c3821a6f76d69430"},{"id":"CVE-2016-10050-c7798fe4","target":{"file":"coders/rle.c"},"digest":{"line_hashes":["267126696522631243637154053117559899847","194685861941463828697209183016499384540","324653638925418779892666715507618860882","124485125922039252038167889184296040858","85106562968262129759488476083529397733","157662687178047085674125175844961650042","142050422640354494791364593205432372508","54384164121269514477325327768581846008","245726469203549136635487596723735688689","466965525889268471860395757970274732","293936090464199042141228148819271545063","185171254139728529170985282759243646696","119369566322523715329684826529429485502","204846801654535442630177278878898656111","160821126149538071051277242024380796076","293936090464199042141228148819271545063","44609005223077563065981326035523619544","80764522418760111161312775892560066612","312133404824105457475069843275559323779","96960317885383337514161779214108713734","164537079167020457061907602852828314021","169598984756786969344223388527239717849"],"threshold":0.9},"deprecated":false,"signature_version":"v1","signature_type":"Line","source":"https://github.com/imagemagick/imagemagick/commit/73fb0aac5b958521e1511e179ecc0ad49f70ebaf"},{"id":"CVE-2016-10050-f3b45641","target":{"file":"coders/rle.c"},"digest":{"line_hashes":["267126696522631243637154053117559899847","194685861941463828697209183016499384540","324653638925418779892666715507618860882","124485125922039252038167889184296040858","85106562968262129759488476083529397733","157662687178047085674125175844961650042","142050422640354494791364593205432372508","54384164121269514477325327768581846008","245726469203549136635487596723735688689","466965525889268471860395757970274732","293936090464199042141228148819271545063","54384164121269514477325327768581846008","245726469203549136635487596723735688689","466965525889268471860395757970274732","293936090464199042141228148819271545063"],"threshold":0.9},"deprecated":false,"signature_version":"v1","signature_type":"Line","source":"https://github.com/imagemagick/imagemagick/commit/139d4323c40d7363bfdd2382c3821a6f76d69430"},{"id":"CVE-2016-10050-ff22ffb3","target":{"file":"coders/rle.c","function":"ReadRLEImage"},"digest":{"length":10700,"function_hash":"330416355882722401432506661432146686421"},"deprecated":false,"signature_version":"v1","signature_type":"Function","source":"https://github.com/imagemagick/imagemagick/commit/73fb0aac5b958521e1511e179ecc0ad49f70ebaf"}],"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"42.1"}]},{"events":[{"introduced":"0"},{"last_affected":"42.2"}]}],"vanir_signatures_modified":"2026-04-11T03:36:50Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10050.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}