ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/45890/ | exploit vdb entry third party advisory |
https://github.com/ImageMagick/ImageMagick/commit/216d117f05bff87b9dc4db55a1b1fadb38bcb786 | issue tracking third party advisory patch |
https://usn.ubuntu.com/3785-1/ | third party advisory vendor advisory |
https://usn.ubuntu.com/4034-1/ | third party advisory vendor advisory |