CVE-2007-2949: Integer Overflow
Published Jul 4, 2007
·Updated
Integer overflow in the seektoandunpackpixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.
Affected Software
7 affected components
Gimp Gimp<=2.2.15
Ubuntu Linux=7.04
Ubuntu Linux=6.10
Ubuntu Linux=6.06
Ubuntu=6.06
Ubuntu=6.10
Ubuntu=7.04
Remediation
Patch Available
Patch Available
Event History
Jul 4, 2007
CVE Published
03:30 PM
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2949?
CVE-2007-2949 has been classified as having a high severity due to its potential to allow arbitrary code execution by remote attackers.
2
How do I fix CVE-2007-2949?
To fix CVE-2007-2949, upgrade GIMP to the latest version that addresses the integer overflow vulnerability.
3
What versions of GIMP are affected by CVE-2007-2949?
GIMP versions up to and including 2.2.15 are affected by CVE-2007-2949.
4
Can CVE-2007-2949 be exploited through image files?
Yes, CVE-2007-2949 can be exploited by opening a maliciously crafted PSD file with GIMP.
5
What platforms are impacted by CVE-2007-2949?
CVE-2007-2949 affects GIMP on various Linux distributions, including specific versions of Ubuntu.