PT-2012-1072 · Gnu+3 · Gimp+3

Matthias Weckbecker

·

Published

2012-08-20

·

Updated

2023-02-13

·

CVE-2012-3481

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gimp-libs version 2.6.9 gimp-devel-tools version 2.6.9 gimp-help-browser version 2.6.9 gimp-devel version 2.6.9 gimp-debuginfo version 2.6.9 gimp version 2.6.9 gimp version 2.8.x and earlier
Description The issue concerns multiple vulnerabilities in the GIMP software package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially causing a denial of service or allowing the execution of arbitrary code. Specifically, an integer overflow in the ReadImage function in the GIF image format plug-in can trigger a heap-based buffer overflow via crafted height and len properties in a GIF image file.
Recommendations For gimp-libs version 2.6.9, consider updating to a newer version to mitigate the risk. For gimp-devel-tools version 2.6.9, consider updating to a newer version to mitigate the risk. For gimp-help-browser version 2.6.9, consider updating to a newer version to mitigate the risk. For gimp-devel version 2.6.9, consider updating to a newer version to mitigate the risk. For gimp-debuginfo version 2.6.9, consider updating to a newer version to mitigate the risk. For gimp version 2.6.9, consider updating to a newer version to mitigate the risk. For gimp version 2.8.x and earlier, consider updating to a version later than 2.8.x to mitigate the risk. As a temporary workaround, consider restricting the use of the GIF image format plug-in until a patch is available.

Exploit

Fix

DoS

Integer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2015-06186
BDU:2015-06188
BDU:2015-06189
BDU:2015-06190
BDU:2015-06191
BDU:2015-06192
BDU:2015-08769
BDU:2015-08770
BDU:2015-08771
BDU:2015-08772
BDU:2015-08773
BDU:2015-08774
CESA-2012_1180
CVE-2012-3481
OPENSUSE-SU-2012_1080-1
RHSA-2012:1180
RHSA-2012:1181
RHSA-2012_1180
RHSA-2012_1181
SUSE-SU-2012_1038-1

Affected Products

Centos
Gimp
Red Hat
Suse