Описание
A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. A stack-based out-of-bounds write occurs in load_image() because a stack buffer sized as file_size - 0xE0 is later indexed using bounds based on file_size. This can corrupt stack memory and potentially lead to denial of service or arbitrary code execution.
Отчет
A flaw was found in GIMP's Seattle FilmWorks (SFW94A) loader. The load_image() function allocates a stack buffer for file data but later uses larger bounds derived from the full file size, allowing stack memory corruption when a user opens a specially crafted SFW file.
Меры по смягчению последствий
None — requires opening a crafted SFW file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gimp | Not affected | ||
| Red Hat Enterprise Linux 7 | gimp | Not affected | ||
| Red Hat Enterprise Linux 8 | gimp:2.8/gimp | Not affected | ||
| Red Hat Enterprise Linux 9 | gimp | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2497435gimp: gimp: Stack-based out-of-bounds write in Seattle FilmWorks loader
7.3 High
CVSS3
Связанные уязвимости
7.3 High
CVSS3