PT-2012-6333 · Gimp+3 · Libgimpprint+5

Marc Schönefeld

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2012-4405

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libgimpprint versions (affected versions not specified) libgimpprint-devel versions (affected versions not specified) libgimpprint-debuginfo versions (affected versions not specified)
Description The issue is related to the exploitation of a vulnerability in the libgimpprint package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. This vulnerability can be exploited remotely. Additionally, there are multiple integer underflows in the icmLut allocate function in the International Color Consortium (ICC) Format library, which can cause a denial of service and possibly execute arbitrary code via crafted PostScript or PDF files with embedded images.
Recommendations For libgimpprint, consider disabling the vulnerable package until a patch is available. For libgimpprint-devel, restrict access to the vulnerable package to minimize the risk of exploitation. For libgimpprint-debuginfo, avoid using the package until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04375
BDU:2015-04376
BDU:2015-05499
BDU:2015-05500
BDU:2015-05501
CESA-2012_1256
CVE-2012-4405
DSA-2595-1
OPENSUSE-SU-2012_1289-1
RHSA-2012:1256
RHSA-2012_1256
SUSE-SU-2012_1222-1

Affected Products

Centos
Red Hat
Suse
Libgimpprint
Libgimpprint-Debuginfo
Libgimpprint-Devel