Описание
A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. In load_image(), photo_date is allocated based on an unvalidated metadata separator offset and can become a 1-byte buffer before fread() writes the full metadata span into it. This could lead to heap memory corruption, potentially resulting in denial of service or arbitrary code execution.
Отчет
A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. A malformed metadata record can cause load_image() to allocate an undersized heap buffer for photo_date before reading a larger metadata span into it. Successful exploitation requires a user to open a specially crafted SFW file.
Меры по смягчению последствий
None — requires opening a crafted SFW file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gimp | Not affected | ||
| Red Hat Enterprise Linux 7 | gimp | Not affected | ||
| Red Hat Enterprise Linux 8 | gimp:2.8/gimp | Not affected | ||
| Red Hat Enterprise Linux 9 | gimp | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2497434gimp: gimp: Heap buffer overflow in Seattle FilmWorks metadata parsing
7.3 High
CVSS3
Связанные уязвимости
7.3 High
CVSS3