Description
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1139-1 | imagemagick security update |
Debian DLA |
DLA-1140-1 | graphicsmagick security update |
Debian DLA |
DLA-1456-1 | graphicsmagick security update |
Debian DSA |
DSA-4032-1 | imagemagick security update |
Debian DSA |
DSA-4040-1 | imagemagick security update |
Debian DSA |
DSA-4321-1 | graphicsmagick security update |
Ubuntu USN |
USN-3681-1 | ImageMagick vulnerabilities |
Ubuntu USN |
USN-4232-1 | GraphicsMagick vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:50:16.492Z
Reserved: 2017-10-11T00:00:00.000Z
Link: CVE-2017-15277
No data.
Status : Deferred
Published: 2017-10-12T08:29:00.290
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-15277
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN