REDHAT-BUG-2459779: Buffer Overflow
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2459779?
The severity of REDHAT-BUG-2459779 is medium, with a score of 4.
How do I fix REDHAT-BUG-2459779?
To fix REDHAT-BUG-2459779, update the GIMP file-png plugin to the latest version that addresses this vulnerability.
What impact does REDHAT-BUG-2459779 have on GIMP?
REDHAT-BUG-2459779 can lead to a stack-based buffer overflow in the GIMP file-png plugin, potentially causing crashes.
Can REDHAT-BUG-2459779 be exploited remotely?
Yes, a remote attacker can exploit REDHAT-BUG-2459779 by sending a crafted APNG image.
What is the nature of the flaw in REDHAT-BUG-2459779?
The flaw in REDHAT-BUG-2459779 involves an oversized tRNS chunk in an APNG file, leading to a buffer overflow in the file-png plugin.