Описание
A flaw was found in GIMP's PVR decoder. A heap-based out-of-bounds write occurs in pvr_decode_compressed() because the Y-axis loop uses width / 2 instead of height / 2, allowing crafted non-square textures to write past the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
Отчет
A flaw was found in GIMP's PVR decoder. An incorrect loop bound in pvr_decode_compressed() can cause heap memory corruption when a user opens a specially crafted non-square compressed PVR texture. Successful exploitation requires user interaction to open a malicious file.
Меры по смягчению последствий
None — requires opening a crafted PVR file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gimp | Not affected | ||
| Red Hat Enterprise Linux 7 | gimp | Not affected | ||
| Red Hat Enterprise Linux 8 | gimp:2.8/gimp | Not affected | ||
| Red Hat Enterprise Linux 9 | gimp | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2497432gimp: gimp: Heap buffer overflow in pvr_decode_compressed()
7.3 High
CVSS3
Связанные уязвимости
7.3 High
CVSS3