CVE-2017-15277

Description

ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
50.442

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.6Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.6Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.6Windows
collection of image processing tools (USN-4232-1) graphicsmagick_1.3.23-1ubuntu0.4_i386.debLinux
collection of image processing tools (USN-4232-1) graphicsmagick_1.3.23-1ubuntu0.4_amd64.debLinux
collection of image processing tools (USN-4232-1) libgraphicsmagick-q16-3_1.3.23-1ubuntu0.4_i386.debLinux
collection of image processing tools (USN-4232-1) libgraphicsmagick-q16-3_1.3.23-1ubuntu0.4_amd64.debLinux
collection of image processing tools (USN-4232-1) libgraphicsmagick++-q16-12_1.3.23-1ubuntu0.4_i386.debLinux
collection of image processing tools (USN-4232-1) libgraphicsmagick++-q16-12_1.3.23-1ubuntu0.4_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234