Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-3236

Опубликовано: 29 июн. 2012
Источник: redhat
CVSS2: 4.3

Описание

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.

Отчет

We do not consider a user-assisted crash of a client application such as Gimp to be a security issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gimpNot affected
Red Hat Enterprise Linux 6gimpNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=834627gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.

nvd
больше 13 лет назад

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.

debian
больше 13 лет назад

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a deni ...

github
больше 3 лет назад

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.

4.3 Medium

CVSS2