PT-2012-1093 · Gnome+4 · Gegl+4

Jan Lieskovsky

+1

·

Published

2012-11-12

·

Updated

2024-06-15

·

CVE-2012-4433

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GEGL versions 0.1.2 through 0.2.0 GEGL version 0.1.2
Description The issue affects the GEGL library, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via a large width or height value in a Portable Pixel Map image. This triggers a heap-based buffer overflow. The vulnerability can lead to a disruption of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely.
Recommendations For GEGL versions 0.1.2, consider disabling the use of Portable Pixel Map images until a patch is available. For GEGL versions 0.1.2, restrict access to the operations/external/ppm-load.c module to minimize the risk of exploitation. For GEGL version 0.2.0, avoid using large width or height values in Portable Pixel Map images until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1716
BDU:2015-07214
BDU:2015-07215
BDU:2015-07216
BDU:2015-08882
BDU:2015-08883
BDU:2015-08884
CESA-2012_1455
CVE-2012-4433
OPENSUSE-SU-2024:10782-1
RHSA-2012:1455
RHSA-2012_1455
SUSE-SU-2017:0694-1
SUSE-SU-2017:0696-1
SUSE-SU-2017_0694-1
SUSE-SU-2017_0696-1

Affected Products

Alt Linux
Centos
Gegl
Red Hat
Suse