First published: Tue Jul 10 2012(Updated: )
A heap-based buffer overflow flaw, leading to invalid free, was found in the way KISS CEL file format plug-in of Gimp, the GNU Image Manipulation Program, performed loading of certain palette files. A remote attacker could provide a specially-crafted KISS palette file that, when opened in Gimp would cause the CEL plug-in to crash or, potentially, execute arbitrary code with the privileges of the user running the gimp executable. Issue found by: Murray McAllister, Red Hat Security Response Team
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GIMP GIMP | <=2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.