The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a denial of service (buffer over-read) by sending a crafted JPEG file.
https://www.debian.org/security/2017/dsa-4040
https://www.debian.org/security/2017/dsa-4032
https://usn.ubuntu.com/3681-1/