ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.
[
{
"source": "https://github.com/imagemagick/imagemagick/commit/9fd10cf630832b36a588c1545d8736539b2f1fb5",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"306973232245618165981768373290104851468",
"125207226614535232036573969069490306158",
"29907257949769001391588402564807748975",
"314517929402371445594822948285256751638"
]
},
"id": "CVE-2017-15277-18d632c1",
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "coders/gif.c"
}
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/9fd10cf630832b36a588c1545d8736539b2f1fb5",
"deprecated": false,
"digest": {
"function_hash": "295666413879762265196560470791931146085",
"length": 9760.0
},
"id": "CVE-2017-15277-ec5bd8a7",
"signature_type": "Function",
"signature_version": "v1",
"target": {
"function": "ReadGIFImage",
"file": "coders/gif.c"
}
}
]