PT-2012-6333 · Gimp+3 · Libgimpprint+5
Marc Schönefeld
·
Published
1970-01-01
·
Updated
2023-02-13
·
CVE-2012-4405
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libgimpprint versions (affected versions not specified)
libgimpprint-devel versions (affected versions not specified)
libgimpprint-debuginfo versions (affected versions not specified)
Description
The issue is related to the exploitation of a vulnerability in the libgimpprint package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. This vulnerability can be exploited remotely. Additionally, there are multiple integer underflows in the icmLut allocate function in the International Color Consortium (ICC) Format library, which can cause a denial of service and possibly execute arbitrary code via crafted PostScript or PDF files with embedded images.
Recommendations
For libgimpprint, consider disabling the vulnerable package until a patch is available.
For libgimpprint-devel, restrict access to the vulnerable package to minimize the risk of exploitation.
For libgimpprint-debuginfo, avoid using the package until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Libgimpprint
Libgimpprint-Debuginfo
Libgimpprint-Devel