CVE-2026-102635
MEDIUM
6,3
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information.
908
Use of Uninitialized Resource
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Availability
Potential Impacts:
Read Memory
Read Application Data
Dos: Crash, Exit, Or Restart
Applicable Platforms
All platforms may be affected
https://github.com/ImageMagick/ImageMagick
https://github.com/ImageMagick/ImageMagick6/commit/95dc0fd21a684bfac2bdb6fb6638…
https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/coders/gif.c#L1168-L11…
https://github.com/ImageMagick/ImageMagick/commit/a0ca2c739c0216ff4efbd631d1ba7…
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvv7-5mh8-v…
https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-…