PT-2012-6333 · Gimp+3 · Libgimpprint+5
Marc Schönefeld
·
Publicado
1970-01-01
·
Atualizado
2023-02-13
·
CVE-2012-4405
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libgimpprint versions (affected versions not specified)
libgimpprint-devel versions (affected versions not specified)
libgimpprint-debuginfo versions (affected versions not specified)
Description
The issue is related to the exploitation of a vulnerability in the libgimpprint package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. This vulnerability can be exploited remotely. Additionally, there are multiple integer underflows in the icmLut allocate function in the International Color Consortium (ICC) Format library, which can cause a denial of service and possibly execute arbitrary code via crafted PostScript or PDF files with embedded images.
Recommendations
For libgimpprint, consider disabling the vulnerable package until a patch is available.
For libgimpprint-devel, restrict access to the vulnerable package to minimize the risk of exploitation.
For libgimpprint-debuginfo, avoid using the package until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Suse
Libgimpprint
Libgimpprint-Debuginfo
Libgimpprint-Devel