CVE-2017-15277Sensitive Information Exposure in Graphicsmagick

Severity
6.5MEDIUMNVD
EPSS
59.3%
top 1.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateMay 14

Description

ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

debiandebian/imagemagick< graphicsmagick 1.3.26-14 (bookworm)
debiandebian/graphicsmagick< graphicsmagick 1.3.26-14 (bookworm)
Debianimagemagick/imagemagick< 8:6.9.9.34+dfsg-3+3
Debiangraphicsmagick/graphicsmagick< 1.3.26-14+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-844h-5pcp-3xmc: ReadGIFImage in coders/gif2022-05-14
OSV
CVE-2017-15277: ReadGIFImage in coders/gif2017-10-12

📋Vendor Advisories

4
Ubuntu
GraphicsMagick vulnerabilities2020-01-08
Ubuntu
ImageMagick vulnerabilities2018-06-12
Red Hat
ImageMagick: Unitialized palette in ReadGIFImage when processing a crafted GIF file2017-07-21
Debian
CVE-2017-15277: graphicsmagick - ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 le...2017

💬Community

3
HackerOne
ImageMagick GIF coder vulnerability leading to memory disclosure2018-07-02
HackerOne
CVE-2017-15277 on Profile page2018-03-08
Bugzilla
CVE-2017-15277 ImageMagick: Unitialized palette in ReadGIFImage when processing a crafted GIF file2017-11-07