CVE Vulnerabilities

CVE-2017-9098

Use of Uninitialized Resource

Published: May 19, 2017 | Modified: Apr 28, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.1 MODERATE
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Imagemagick Imagemagick * 6.9.8-1 (excluding)
Imagemagick Imagemagick 7.0.0-0 (including) 7.0.5-2 (excluding)
Imagemagick Ubuntu devel *
Imagemagick Ubuntu trusty *
Imagemagick Ubuntu upstream *
Imagemagick Ubuntu xenial *
Imagemagick Ubuntu yakkety *
Imagemagick Ubuntu zesty *

Potential Mitigations

References