oss-sec mailing list archives
Re: CVE request for buffer overflows in gimp
From: Josh Bressers <bressers () redhat com>
Date: Tue, 4 Jan 2011 09:04:52 -0500 (EST)
----- Original Message -----
Hello Steve, Vendors, This one is from the debian bug tracker [1], there are four buffer overflows in gimp plugins. I am not sure if this would need one CVE or four? [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497
I'm going to give this four. We *might* be able to get away with two, but since they're all in quite different bits of code, I'm betting the affected versions are different, and it's likely upstream is going to fix these all at different times in their SCM. CVE-2010-4540 gimp LIGHTING EFFECTS > LIGHT plugin stack buffer overflow CVE-2010-4541 gimp SPHERE DESIGNER plugin stack buffer overflow CVE-2010-4542 gimp GFIG plugin stack buffer overflow CVE-2010-4543 gimp heap overflow read_channel_data() in file-psp.c Thanks. -- JB
Current thread:
- CVE request for buffer overflows in gimp Huzaifa Sidhpurwala (Jan 03)
- Re: CVE request for buffer overflows in gimp Josh Bressers (Jan 04)