CVE-2017-17785: Buffer Overflow
Published Dec 20, 2017
·Updated
In GIMP 2.8.22, there is a heap-based buffer overflow in the flireadbrun function in plug-ins/file-fli/fli.c.
Affected Software
6 affected componentsFixes available
GIMP GIMP=2.8.22
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
debian/gimp
2.10.22-4+deb11u22.10.22-4+deb11u62.10.34-1+deb12u52.10.34-1+deb12u83.0.4-3+deb13u23.0.4-3+deb13u63.2.0~RC2-3.13.2.0~RC2-3.3
Event History
Dec 20, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
09:24 AM
SeverityAffected Software
Data Sourced
via NVD·09:29 AM
DescriptionSeverityWeaknessAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·10:07 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:08 PM
DescriptionAffected Software
Data Sourced
via Launchpad·10:08 PM
Description
Frequently Asked Questions
1
What is CVE-2017-17785?
CVE-2017-17785 is a vulnerability in GIMP 2.8.22 that allows for a heap-based buffer overflow in the fli_read_brun function.
2
How severe is CVE-2017-17785?
CVE-2017-17785 has a severity rating of 7.8 (High).
3
Which software versions are affected by CVE-2017-17785?
CVE-2017-17785 affects GIMP 2.8.22.
4
How can I fix CVE-2017-17785?
To fix CVE-2017-17785, you should update GIMP to version 2.10.8-2, 2.10.22-4, or 2.10.34-1.
5
Where can I find more information about CVE-2017-17785?
You can find more information about CVE-2017-17785 at the following references: [Openwall](http://www.openwall.com/lists/oss-security/2017/12/19/5), [GNOME Bugzilla](https://bugzilla.gnome.org/show_bug.cgi?id=739133), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2017/12/msg00023.html).