CVE-2017-17784: High severity GIMP GIMP vulnerability
Published Dec 20, 2017
·Updated
In GIMP 2.8.22, there is a heap-based buffer over-read in loadimage in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
Affected Software
6 affected componentsFixes available
GIMP GIMP=2.8.22
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
debian/gimp
2.10.22-4+deb11u22.10.22-4+deb11u62.10.34-1+deb12u52.10.34-1+deb12u83.0.4-3+deb13u23.0.4-3+deb13u63.2.0~RC2-3.13.2.0~RC2-3.3
Event History
Dec 20, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
via NVD·09:29 AM
DescriptionSeverityWeaknessAffected Software
Dec 21, 2017
Data Sourced
01:09 PM
SeverityAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·10:07 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:08 PM
DescriptionAffected Software
Data Sourced
via Launchpad·10:08 PM
Description
Frequently Asked Questions
1
What is CVE-2017-17784?
CVE-2017-17784 is a vulnerability in GIMP 2.8.22 that allows for a heap-based buffer over-read in the gbr import parser.
2
How does CVE-2017-17784 occur?
CVE-2017-17784 occurs due to mishandling of UTF-8 data in the load_image function in plug-ins/common/file-gbr.c.
3
What is the severity of CVE-2017-17784?
The severity of CVE-2017-17784 is high with a CVSS score of 7.8.
4
Which versions of GIMP are affected by CVE-2017-17784?
GIMP versions 2.8.22 and below are affected by CVE-2017-17784.
5
How can I fix CVE-2017-17784?
To fix CVE-2017-17784, update GIMP to version 2.10.8-2, 2.10.22-4, or 2.10.34-1 on Debian, or version 2.8.10-0ubuntu1.2 on Ubuntu.