Описание
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
Multiple use-after-free vulnerabilities were found in GIMP in the channel and layer properties parsing process when loading XCF files. An attacker could create a specially crafted XCF file which could cause GIMP to crash.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | gimp | Will not fix | ||
Red Hat Enterprise Linux 6 | gimp | Will not fix | ||
Red Hat Enterprise Linux 7 | gimp | Fixed | RHSA-2016:2589 | 03.11.2016 |
Red Hat Enterprise Linux 7 | gimp-help | Fixed | RHSA-2016:2589 | 03.11.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.5 Low
CVSS3
2.6 Low
CVSS2
Связанные уязвимости
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
Use-after-free vulnerability in the xcf_load_image function in app/xcf ...
EPSS
2.5 Low
CVSS3
2.6 Low
CVSS2