LWN.net Logo

gegl: code execution

Package(s):gegl CVE #(s):CVE-2012-4433
Created:November 13, 2012 Updated:January 23, 2013
Description: From the Red Hat advisory:

An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way the gegl utility processed .ppm (Portable Pixel Map) image files. An attacker could create a specially-crafted .ppm file that, when opened in gegl, would cause gegl to crash or, potentially, execute arbitrary code.

Alerts:
Red Hat RHSA-2012:1455-01 2012-11-12
CentOS CESA-2012:1455 2012-11-12
Scientific Linux SL-gegl-20121112 2012-11-12
Oracle ELSA-2012-1455 2012-11-12
Mageia MGASA-2012-0335 2012-11-21
openSUSE openSUSE-SU-2012:1627-1 2012-12-07
openSUSE openSUSE-SU-2013:0159-1 2013-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds