First published: Mon Jan 22 2018(Updated: )
It was discovered that GIMP incorrectly handled certain images. If a user were tricked into opening a specially crafted image, an attacker could possibly use this to execute arbitrary code. (CVE-2017-17784, CVE-2017-17785, CVE-2017-17786, CVE-2017-17787, CVE-2017-17788, CVE-2017-17789)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/gimp | <2.8.10-0ubuntu1.2 | 2.8.10-0ubuntu1.2 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/libgimp2.0 | <2.8.10-0ubuntu1.2 | 2.8.10-0ubuntu1.2 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for GIMP vulnerabilities is CVE-2017-17784, CVE-2017-17785, CVE-2017-17786, CVE-2017-17787, CVE-2017-17788, and CVE-2017-17789.
The affected software for USN-3539-1 is GIMP version 2.8.10-0ubuntu1.2 and libgimp2.0 version 2.8.10-0ubuntu1.2 on Ubuntu 14.04.
The severity of the GIMP vulnerabilities is not specified.
An attacker can exploit the GIMP vulnerabilities by tricking a user into opening a specially crafted image, potentially allowing them to execute arbitrary code.
To fix the GIMP vulnerabilities, you should update GIMP and libgimp2.0 to version 2.8.10-0ubuntu1.2 or later on Ubuntu 14.04.