LWN.net Logo

gimp: multiple vulnerabilities

Package(s):gimp CVE #(s):CVE-2012-2763 CVE-2012-3236
Created:September 4, 2012 Updated:November 9, 2012
Description: From the

Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server. (CVE-2012-2763)

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string. (CVE-2012-3236)

Alerts:
openSUSE openSUSE-SU-2012:1080-1 2012-09-03
openSUSE openSUSE-SU-2012:1131-1 2012-09-07
Ubuntu USN-1559-1 2012-09-10
Gentoo 201209-23 2012-09-28
Mageia MGASA-2012-0286 2012-10-06
Mageia MGASA-2012-0327 2012-11-09
Mandriva MDVSA-2013:082 2013-04-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds