Imagemagick GIF coder vulnerability leads to memory disclosure
In Summary : “Imagemagick gif exploit (CVE-2017–15277) is a type of vulnerability which affects the outdated version of ImageMagick 7.0...
https://updatesinfosec.blogspot.com/2018/11/imagemagick-gif-coder-vulnerability.html
In Summary :
kindly refer the following link as follow up :
https://medium.com/@kunal94/imagemagick-gif-coder-vulnerability-leads-to-memory-disclosure-hackerone-e9975a6a560e?source=twitterShare-1764222123d3-1541968602&_branch_match_id=540891355441283646
“Imagemagick
gif exploit (CVE-2017–15277) is a type of vulnerability which affects
the outdated version of ImageMagick 7.0.6–1 and Graphicsmagick 1.3.26
leaves the palette uninitialized when processing a GIF file that has
neither a global nor local palette. If the affected product is used as a
library loaded into a process that operates on interesting data, this
data sometimes can be leaked via the uninitialized palette.”
Putting
it in more simple words, There was server memory leakage for this
outdated version of Imagemagick 7.0.6–1 and Graphicsmagick (fault in
library processing ) in which you can create exploitable image file,
upload to any area around webpage and if you get uninitialized [...]kindly refer the following link as follow up :
https://medium.com/@kunal94/imagemagick-gif-coder-vulnerability-leads-to-memory-disclosure-hackerone-e9975a6a560e?source=twitterShare-1764222123d3-1541968602&_branch_match_id=540891355441283646
