Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-30067

Опубликовано: 17 мая 2022
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

A vulnerability was found in GIMP. Via a specially crafted XCF file, GIMP can allocate a large amount of memory, potentially resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7gimpOut of support scope
Red Hat Enterprise Linux 8gimp:2.8/gimpAffected
Red Hat Enterprise Linux 8gimp:flatpak/gimpAffected
Red Hat Enterprise Linux 9gimpFixedRHSA-2022:797815.11.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-252->CWE-770->CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2087591gimp: buffer overflow through a crafted XCF file

EPSS

Процентиль: 18%
0.00058
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

CVSS3: 5.5
nvd
около 3 лет назад

GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

CVSS3: 5.5
debian
около 3 лет назад

GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a ...

suse-cvrf
около 3 лет назад

Security update for gimp

suse-cvrf
около 3 лет назад

Security update for gimp

EPSS

Процентиль: 18%
0.00058
Низкий

6.2 Medium

CVSS3