CVE-2010-4542: Buffer Overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4542 to the following vulnerability:
Stack-based buffer overflow in the gfigreadparametergimprgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Foreground field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself. NOTE: some of these details are obtained from third party information.
References: [1] http://openwall.com/lists/oss-security/2011/01/03/2 [2] http://openwall.com/lists/oss-security/2011/01/04/7 [3] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497 [4] https://bugzilla.redhat.com/showbug.cgi?id=666793 [5] http://osvdb.org/70283 [6] http://secunia.com/advisories/42771 [7] http://www.vupen.com/english/advisories/2011/0016
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2010-4542?
CVE-2010-4542 is classified as a medium severity vulnerability due to its potential to cause application crashes and allow arbitrary code execution.
How do I fix CVE-2010-4542?
To fix CVE-2010-4542, update GIMP to version 2.6.12 or later, which contains the necessary security patches.
What systems are affected by CVE-2010-4542?
CVE-2010-4542 affects GIMP version 2.6.11 and earlier, specifically on Red Hat Enterprise Linux versions el5 and el6.
What type of attack does CVE-2010-4542 allow?
CVE-2010-4542 allows user-assisted remote attackers to exploit the vulnerability to cause denial of service or execute arbitrary code.
Who is responsible for addressing CVE-2010-4542?
Vendors of affected GIMP versions and their distributions, like Red Hat, are responsible for providing patches and updates to address CVE-2010-4542.