PT-2011-2924 · Gnu+1 · Gimp+1

Jan Lieskovsky

·

Published

2011-05-31

·

Updated

2023-02-13

·

CVE-2011-1178

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GIMP versions 2.6.x and earlier
Description The issue is caused by multiple integer overflows in the load image function in the Personal Computer Exchange (PCX) plugin, which can lead to a denial of service (application crash) or possibly allow execution of arbitrary code. This can be triggered by a crafted PCX image that causes a heap-based buffer overflow.
Recommendations For GIMP versions 2.6.x and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, avoid using the PCX plugin to open potentially malicious images until a patch is available.

Fix

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2011-1178
RHSA-2011:0837
RHSA-2011:0838
RHSA-2011_0837
RHSA-2011_0838

Affected Products

Gimp
Red Hat