Описание
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| gimp | fixed | 3.2.2-1 | package | |
| gimp | not-affected | trixie | package | |
| gimp | not-affected | bookworm | package | |
| gimp | not-affected | bullseye | package |
Примечания
https://gitlab.gnome.org/GNOME/gimp/-/issues/16076
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/51f1de884407645df64e8ce8490e25f905fde323 (GIMP_3_2_2)
Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/6395c37425cc2bf81300ffffadc9e3e75f6c0ecd (GIMP_3_1_2)
EPSS
Связанные уязвимости
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.
EPSS