In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.
{ "vanir_signatures": [ { "id": "CVE-2017-13143-400aace6", "signature_type": "Line", "target": { "file": "coders/mat.c" }, "deprecated": false, "digest": { "line_hashes": [ "20662938386431963903059203495908790774", "6112105038936826030440459592959447312", "105585589862511746932701877208014814379", "318116630817013109098708747648370231226" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/imagemagick/imagemagick/commit/51b0ae01709adc1e4a9245e158ef17b85a110960" }, { "id": "CVE-2017-13143-80093cc5", "signature_type": "Function", "target": { "file": "coders/mat.c", "function": "ReadMATImage" }, "deprecated": false, "digest": { "length": 11305.0, "function_hash": "51831393701131582908251375804939290330" }, "signature_version": "v1", "source": "https://github.com/imagemagick/imagemagick/commit/51b0ae01709adc1e4a9245e158ef17b85a110960" } ] }