The attached image causes an info leak in image inflation. It occasionally crashes when rendered, otherwise it displays uninitialized memory as pixels.

To reproduce, put the attached images on a webserver and vist: http://127.0.0.1?img=inflate.png.


Proof of Concept:
https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/44528.zip