PT-2006-4295 · Gnu+1 · Gimp+1

Henning Makholm

·

Published

2006-07-06

·

Updated

2024-06-15

·

CVE-2006-3404

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Gimp versions prior to 2.2.12
Description The issue is related to a buffer overflow in the xcf load vector function, which can be triggered by an XCF file containing a large num axes value in the VECTORS property. This could allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code.
Recommendations For versions prior to 2.2.12, update to version 2.2.12 or later to resolve the issue. As a temporary workaround, consider avoiding the use of XCF files with large num axes values in the VECTORS property until the update is applied.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-3404
DSA-1116
OPENSUSE-SU-2024:10785-1
RHSA-2006:0598
RHSA-2006_0598

Affected Products

Gimp
Red Hat