REDHAT-BUG-2507557: Medium severity GIMP file-icns plugin vulnerability
A flaw was found in the file-icns plugin in GIMP, affecting versions 2.99.14 and newer. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icnsdecompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2507557?
The severity of REDHAT-BUG-2507557 is medium, rated at 4.
How do I fix REDHAT-BUG-2507557?
To fix REDHAT-BUG-2507557, ensure you update to a patched version of the GIMP file-icns plugin that addresses the vulnerability.
What versions of GIMP are affected by REDHAT-BUG-2507557?
The affected versions of GIMP related to REDHAT-BUG-2507557 are 2.99.14 and newer.
What kind of flaw is described in REDHAT-BUG-2507557?
REDHAT-BUG-2507557 describes a flaw in the file-icns plugin where the plugin does not verify cursor limits when processing a mask, potentially leading to buffer over-read.
What are the potential risks of REDHAT-BUG-2507557?
The potential risks of REDHAT-BUG-2507557 include exploitation through crafted files that may lead to unintended data exposure or application instability.