Описание
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 2.8.22-1 |
| cosmic | not-affected | 2.8.22-1 |
| devel | not-affected | 2.8.22-1 |
| disco | not-affected | 2.8.22-1 |
| eoan | not-affected | 2.8.22-1 |
| esm-apps/bionic | not-affected | 2.8.22-1 |
| esm-apps/focal | not-affected | 2.8.22-1 |
| esm-apps/jammy | not-affected | 2.8.22-1 |
| esm-apps/noble | not-affected | 2.8.22-1 |
Показывать по
Ссылки на источники
4.3 Medium
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_st ...
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
Уязвимость функции xcf_load_stream графического редактора GIMP, связанная с чтением за границами буфера памяти, позволяющая нарушителю вызвать отказ в обслуживании, нарушить целостность и конфиденциальность данных
4.3 Medium
CVSS2
5.5 Medium
CVSS3