In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode function.
https://www.debian.org/security/2018/dsa-4245
https://www.debian.org/security/2018/dsa-4204
https://usn.ubuntu.com/3681-1/