REDHAT-BUG-839020: Buffer Overflow
A heap-based buffer overflow flaw, leading to invalid free, was found in the way KISS CEL file format plug-in of Gimp, the GNU Image Manipulation Program, performed loading of certain palette files. A remote attacker could provide a specially-crafted KISS palette file that, when opened in Gimp would cause the CEL plug-in to crash or, potentially, execute arbitrary code with the privileges of the user running the gimp executable.
Issue found by: Murray McAllister, Red Hat Security Response Team
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-839020?
REDHAT-BUG-839020 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix REDHAT-BUG-839020?
To mitigate REDHAT-BUG-839020, update the GIMP software to the latest patched version provided by the vendor.
What versions of GIMP are affected by REDHAT-BUG-839020?
REDHAT-BUG-839020 affects specific earlier versions of GIMP that utilize the KISS CEL file format plug-in.
Can REDHAT-BUG-839020 be exploited remotely?
Yes, REDHAT-BUG-839020 can be exploited remotely if a malicious KISS palette file is opened in GIMP.
What type of vulnerability is REDHAT-BUG-839020?
REDHAT-BUG-839020 is a heap-based buffer overflow vulnerability leading to an invalid free condition.