First published: Tue Mar 22 2011(Updated: )
An integer overflow, leading to heap-based buffer overflow, was found in The Gimp's Personal Computer eXchange (PCX) image file plug-in. A remote attacker could provide a specially-crafted PCX image file, which once opened by a local, unsuspecting user would lead to denial of service (GIMP PCX plug-in crash) or, potentially, arbitrary code execution with the privileges of the user running Gimp.
Affected Software | Affected Version | How to fix |
---|---|---|
GIMP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-689831 is a high severity vulnerability due to the potential for remote denial of service.
To fix REDHAT-BUG-689831, update to the latest version of GIMP that contains the security patch.
Users of GIMP who open PCX image files from untrusted sources are impacted by REDHAT-BUG-689831.
REDHAT-BUG-689831 is categorized as an integer overflow leading to a heap-based buffer overflow.
Yes, a remote attacker can exploit REDHAT-BUG-689831 by providing a specially-crafted PCX image file.