Описание
A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file sets bits-per-pixel to 0, causing the unpack loop to never advance and to write indefinitely past the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Отчет
A flaw was found in GIMP's Jeff's Image Format (JIF) parser. When a crafted JIF file sets bits-per-pixel to 0, the unpack loop in ReadJeffsImage() never advances and writes past the destination buffer, leading to memory corruption. Successful exploitation requires a user to open a specially crafted JIF file in a build that includes the JIF import path.
Меры по смягчению последствий
None — requires opening a crafted JIF/GIF file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gimp | Not affected | ||
| Red Hat Enterprise Linux 7 | gimp | Not affected | ||
| Red Hat Enterprise Linux 8 | gimp:2.8/gimp | Not affected | ||
| Red Hat Enterprise Linux 9 | gimp | Not affected |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
7.3 High
CVSS3