gimp: arbitrary code execution
Package(s): | gimp |
CVE #(s): | CVE-2011-1178
|
Created: | May 31, 2011 |
Updated: | September 28, 2012 |
Description: |
From the Red Hat advisory:
An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the GIMP's Microsoft Windows Bitmap (BMP) and Personal Computer
eXchange (PCX) image file plug-ins. An attacker could create a
specially-crafted BMP or PCX image file that, when opened, could cause the
relevant plug-in to crash or, potentially, execute arbitrary code with the
privileges of the user running the GIMP. |
Alerts: |
|