CVE-2017-17786: High severity GIMP GIMP vulnerability
Published Dec 20, 2017
·Updated
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
Affected Software
6 affected componentsFixes available
GIMP GIMP=2.8.22
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
debian/gimp
2.10.22-4+deb11u22.10.22-4+deb11u62.10.34-1+deb12u52.10.34-1+deb12u83.0.4-3+deb13u23.0.4-3+deb13u63.2.0~RC2-3.13.2.0~RC2-3.3
Event History
Dec 20, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
via NVD·09:29 AM
DescriptionSeverityWeaknessAffected Software
Data Sourced
04:27 PM
SeverityAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·10:07 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:08 PM
DescriptionAffected Software
Data Sourced
via Launchpad·10:08 PM
Description
Frequently Asked Questions
1
What is CVE-2017-17786?
CVE-2017-17786 is a vulnerability in GIMP 2.8.22 that allows heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c.
2
How does CVE-2017-17786 affect GIMP?
CVE-2017-17786 affects GIMP version 2.8.22, allowing unexpected bits-per-pixel value for an RGBA image.
3
What is the severity of CVE-2017-17786?
The severity of CVE-2017-17786 is high, with a severity value of 7.8.
4
How can I fix CVE-2017-17786?
To fix CVE-2017-17786, upgrade to a version of GIMP that is not affected by the vulnerability.
5
Where can I find more information about CVE-2017-17786?
You can find more information about CVE-2017-17786 on the following references: [1] [2] [3].