First published: Tue Jul 10 2012(Updated: )
A heap-based buffer overflow flaw, leading to invalid free, was found in the way KISS CEL file format plug-in of Gimp, the GNU Image Manipulation Program, performed loading of certain palette files. A remote attacker could provide a specially-crafted KISS palette file that, when opened in Gimp would cause the CEL plug-in to crash or, potentially, execute arbitrary code with the privileges of the user running the gimp executable. Issue found by: Murray McAllister, Red Hat Security Response Team
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GIMP | <=2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3403 has a medium severity rating due to the potential for a heap-based buffer overflow.
To fix CVE-2012-3403, update GIMP to version 2.8.1 or higher.
GIMP versions up to and including 2.8.0 are affected by CVE-2012-3403.
CVE-2012-3403 is a heap-based buffer overflow vulnerability in the KISS CEL file format plug-in for GIMP.
An attacker could potentially execute arbitrary code by enticing a user to open a specially-crafted KISS palette file in GIMP.