CVE-2016-4994: Use After Free
Published Jul 12, 2016
·Updated
Use-after-free vulnerability in the xcfloadimage function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
Affected Software
1 affected component
GIMP<2.8.18
Remediation
Event History
Jul 12, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4994?
CVE-2016-4994 is classified as a high-severity vulnerability due to its potential to cause denial of service or allow arbitrary code execution.
2
How do I fix CVE-2016-4994?
To fix CVE-2016-4994, update GIMP to version 2.8.18 or later.
3
What type of vulnerability is CVE-2016-4994?
CVE-2016-4994 is a use-after-free vulnerability found in the xcf_load_image function of GIMP.
4
What are the consequences of exploiting CVE-2016-4994?
Exploiting CVE-2016-4994 can lead to application crashes and may allow attackers to execute arbitrary code.
5
Which software versions are affected by CVE-2016-4994?
CVE-2016-4994 affects GIMP versions prior to 2.8.18.