First published: Tue Jul 10 2012(Updated: )
A heap-based buffer overflow flaw, leading to invalid free, was found in the way KISS CEL file format plug-in of Gimp, the GNU Image Manipulation Program, performed loading of certain palette files. A remote attacker could provide a specially-crafted KISS palette file that, when opened in Gimp would cause the CEL plug-in to crash or, potentially, execute arbitrary code with the privileges of the user running the gimp executable. Issue found by: Murray McAllister, Red Hat Security Response Team
Affected Software | Affected Version | How to fix |
---|---|---|
GIMP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-839020 is classified as a critical vulnerability due to its potential to allow remote code execution.
To mitigate REDHAT-BUG-839020, update the GIMP software to the latest patched version provided by the vendor.
REDHAT-BUG-839020 affects specific earlier versions of GIMP that utilize the KISS CEL file format plug-in.
Yes, REDHAT-BUG-839020 can be exploited remotely if a malicious KISS palette file is opened in GIMP.
REDHAT-BUG-839020 is a heap-based buffer overflow vulnerability leading to an invalid free condition.