{"id":"CVE-2016-7524","details":"coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.","modified":"2026-04-11T05:00:50.570281Z","published":"2020-02-06T14:15:10.830Z","related":["CGA-vvqw-2fqc-prvg","SUSE-SU-2016:2667-1","SUSE-SU-2016:2724-1","SUSE-SU-2016:2964-1"],"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/09/22/2"},{"type":"ADVISORY","url":"https://github.com/ImageMagick/ImageMagick/issues/96"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1378762"},{"type":"FIX","url":"https://github.com/ImageMagick/ImageMagick/commit/97c9f438a9b3454d085895f4d1f66389fd22a0fb"},{"type":"FIX","url":"https://github.com/ImageMagick/ImageMagick/commit/f8c318d462270b03e77f082e2a3a32867cacd3c6"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1537422"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/imagemagick/imagemagick","events":[{"introduced":"0"},{"fixed":"97c9f438a9b3454d085895f4d1f66389fd22a0fb"},{"fixed":"f8c318d462270b03e77f082e2a3a32867cacd3c6"}]},{"type":"GIT","repo":"https://github.com/imagemagick/imagemagick6","events":[{"introduced":"0"},{"fixed":"4bae9bed8a79e031884ca9a4681dce89dbd26855"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"6.9.4-0"}]}}],"database_specific":{"vanir_signatures_modified":"2026-04-11T05:00:50Z","vanir_signatures":[{"id":"CVE-2016-7524-1e2f1041","deprecated":false,"target":{"file":"coders/meta.c","function":"parse8BIM"},"signature_type":"Function","digest":{"length":4124,"function_hash":"150344898127791179683097426169631887692"},"source":"https://github.com/imagemagick/imagemagick/commit/97c9f438a9b3454d085895f4d1f66389fd22a0fb","signature_version":"v1"},{"id":"CVE-2016-7524-7570553f","deprecated":false,"target":{"file":"coders/meta.c"},"signature_type":"Line","digest":{"line_hashes":["167691339985525583363565666452032300896","45010390050127099537028272767857702776","283044322008242413857705249080406776484","187504798351041781971655743990633442789","247770707780678022366882328583142718018","45010390050127099537028272767857702776","49485456244027635680160564707285686331","178233789116906932578859489293663485829"],"threshold":0.9},"source":"https://github.com/imagemagick/imagemagick/commit/f8c318d462270b03e77f082e2a3a32867cacd3c6","signature_version":"v1"},{"id":"CVE-2016-7524-882af1f1","deprecated":false,"target":{"file":"coders/meta.c","function":"parse8BIM"},"signature_type":"Function","digest":{"length":4126,"function_hash":"329609232511700355419785195282894808935"},"source":"https://github.com/imagemagick/imagemagick/commit/f8c318d462270b03e77f082e2a3a32867cacd3c6","signature_version":"v1"},{"id":"CVE-2016-7524-cd513b78","deprecated":false,"target":{"file":"coders/meta.c"},"signature_type":"Line","digest":{"line_hashes":["167691339985525583363565666452032300896","45010390050127099537028272767857702776","283044322008242413857705249080406776484","187504798351041781971655743990633442789","247770707780678022366882328583142718018","45010390050127099537028272767857702776","49485456244027635680160564707285686331","178233789116906932578859489293663485829"],"threshold":0.9},"source":"https://github.com/imagemagick/imagemagick/commit/97c9f438a9b3454d085895f4d1f66389fd22a0fb","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7524.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}