In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.
{ "vanir_signatures": [ { "target": { "file": "coders/mat.c" }, "signature_type": "Line", "source": "https://github.com/imagemagick/imagemagick/commit/51b0ae01709adc1e4a9245e158ef17b85a110960", "id": "CVE-2017-13143-400aace6", "signature_version": "v1", "deprecated": false, "digest": { "line_hashes": [ "20662938386431963903059203495908790774", "6112105038936826030440459592959447312", "105585589862511746932701877208014814379", "318116630817013109098708747648370231226" ], "threshold": 0.9 } }, { "target": { "function": "ReadMATImage", "file": "coders/mat.c" }, "signature_type": "Function", "source": "https://github.com/imagemagick/imagemagick/commit/51b0ae01709adc1e4a9245e158ef17b85a110960", "id": "CVE-2017-13143-80093cc5", "signature_version": "v1", "deprecated": false, "digest": { "function_hash": "51831393701131582908251375804939290330", "length": 11305.0 } } ] }