The SpliceImage function in MagickCore/transform.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (application crash) via a crafted png file. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8897