Описание
A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file supplies an invalid bits-per-pixel value that causes the unpack loop to write beyond the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Отчет
A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap out-of-bounds write in the ReadJeffsImage() function can lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Successful exploitation requires a user to open a specially crafted JIF file with a build that includes the JIF import path.
Меры по смягчению последствий
None — requires opening a crafted JIF/GIF file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gimp | Not affected | ||
| Red Hat Enterprise Linux 7 | gimp | Not affected | ||
| Red Hat Enterprise Linux 8 | gimp:2.8/gimp | Not affected | ||
| Red Hat Enterprise Linux 9 | gimp | Not affected |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
7.3 High
CVSS3