CVE-2017-15277: Infoleak
Last updated 25 August 2025
Other sources
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-15277?
CVE-2017-15277 is a vulnerability in ImageMagick and GraphicsMagick that leaves the palette uninitialized when processing a GIF file without a global or local palette.
What is the severity of CVE-2017-15277?
CVE-2017-15277 has a severity rating of medium with a CVSS score of 6.5.
How does CVE-2017-15277 affect ImageMagick?
CVE-2017-15277 affects ImageMagick versions 7.0.6-1 and later.
How does CVE-2017-15277 affect GraphicsMagick?
CVE-2017-15277 affects GraphicsMagick versions 1.3.26 and later.
Is there a fix for CVE-2017-15277?
Yes, there are patches available for both ImageMagick and GraphicsMagick to address CVE-2017-15277.