CVE-2017-17788: Medium severity GIMP GIMP vulnerability
Published Dec 20, 2017
·Updated
In GIMP 2.8.22, there is a stack-based buffer over-read in xcfloadstream in app/xcf/xcf.c when there is no '\0' character after the version string.
Affected Software
6 affected componentsFixes available
GIMP GIMP=2.8.22
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
debian/gimp
2.10.22-4+deb11u22.10.22-4+deb11u62.10.34-1+deb12u52.10.34-1+deb12u83.0.4-3+deb13u23.0.4-3+deb13u63.2.0~RC2-3.13.2.0~RC2-3.3
Event History
Dec 20, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
via NVD·09:29 AM
DescriptionSeverityWeaknessAffected Software
Dec 26, 2017
Data Sourced
03:00 PM
SeverityAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·10:07 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:08 PM
DescriptionAffected Software
Data Sourced
via Launchpad·10:08 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-17788.
2
What is the severity of CVE-2017-17788?
The severity of CVE-2017-17788 is medium with a CVSS score of 5.5.
3
How does CVE-2017-17788 impact GIMP?
CVE-2017-17788 can cause a stack-based buffer over-read in GIMP 2.8.22 when there is no '\0' character after the version string.
4
Is there a fix available for CVE-2017-17788?
Yes, the following versions of GIMP have been patched: 2.10.8-2, 2.10.22-4, and 2.10.34-1.
5
Where can I find more information about CVE-2017-17788?
You can find more information about CVE-2017-17788 at the following references: http://www.openwall.com/lists/oss-security/2017/12/19/5, https://bugzilla.gnome.org/show_bug.cgi?id=790783, and https://lists.debian.org/debian-lts-announce/2017/12/msg00023.html.