Описание
A flaw was found in GIMP's TIM loader. File-controlled width, height, and palette size values are used directly in multiple variable-length array declarations in load_image(), allowing a crafted TIM file to force oversized stack allocations and memory corruption. This could lead to denial of service or arbitrary code execution.
Отчет
A flaw was found in GIMP's TIM loader. The load_image() function uses file-controlled dimensions directly in stack-based variable-length arrays, which can lead to oversized stack allocations and memory corruption when a user opens a specially crafted TIM file.
Меры по смягчению последствий
None — requires opening a crafted TIM file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gimp | Not affected | ||
| Red Hat Enterprise Linux 7 | gimp | Not affected | ||
| Red Hat Enterprise Linux 8 | gimp:2.8/gimp | Not affected | ||
| Red Hat Enterprise Linux 9 | gimp | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2497433gimp: gimp: Stack overflow via VLAs in load_image()
7.3 High
CVSS3
Связанные уязвимости
7.3 High
CVSS3