oss-sec mailing list archives

CVE Request: Gimp memory corruption vulnerability


From: Andrés Gómez Ramírez <andresgomezram7 () gmail com>
Date: Wed, 21 Nov 2012 12:19:35 -0500

Hello, could a CVE be assigned to this issue?

Name: Gimp memory corruption vulnerability
Software: GIMP 2.8.2
Software link: http://www.gimp.org/ <http://plib.sourceforge.net/>
Vulnerability Type: Memory Corruption

Description:

GIMP 2.8.2 is vulnerable to memory corruption when reading XWD files, which
could lead even to arbitrary code execution.

Upstream fix:
http://git.gnome.org/browse/gimp/commit/?id=2873262fccba12af144ed96ed91be144d92ff2e1
(fixed in master and gimp-2-8)

References:
https://bugzilla.gnome.org/show_bug.cgi?id=687392

Thanks,

Andres Gomez.

Current thread: