Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian: DSA-2426-1 Moderate: GIMP Multiple Buffer Overflow Issues

debian
Calendar Grey March 6, 2012
Debian Logo
GIMP has addressed multiple security flaws that might lead to software crashes and potentially enable malicious code execution by attackers.
Several vulnerabilities have been identified in GIMP, the GNU Image Manipulation Program

Summary

Several vulnerabilities have been identified in GIMP, the GNU Image
Manipulation Program.

CVE-2010-4540
Stack-based buffer overflow in the load_preset_response
function in plug-ins/lighting/lighting-ui.c in the "LIGHTING
EFFECTS > LIGHT" plugin allows user-assisted remote attackers to cause a denial of service (application crash) or possibly
execute arbitrary code via a long Position field in a plugin
configuration file.

CVE-2010-4541
Stack-based buffer overflow in the loadit function in
plug-ins/common/sphere-designer.c in the SPHERE DESIGNER
plugin allows user-assisted remote attackers to cause a denial
of service (application crash) or possibly execute arbitrary
code via a long "Number of lights" field in a plugin
configuration file.

CVE-2010-4542
Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb
function in in the GFIG plugin allows user-assisted remote
attackers to cause a denial of service (application crash) or
possibly execute arbitrary code via a long Foreground f...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: gimp
CVE ID: CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here