Date:         Wed, 26 Sep 2007 14:40:30 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for gimp on SL5.x, SL4.x, SL3,x i386/x86_64
Comments: To: scientific-linux-errata@fnal.gov

Synopsis:	Moderate: gimp security update
Issue date:	RHSA-2007:0513-01
CVE Names:	CVE-2006-4519 CVE-2007-2949 CVE-2007-3741

Multiple integer overflow and input validation flaws were found in The
GIMP's image loaders.  An attacker could create a carefully crafted image
file that could cause The GIMP to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2006-4519, CVE-2007-2949,
CVE-2007-3741)

SL 3.0.x

   SRPMS:
gimp-1.2.3-20.9.el3.src.rpm
   i386:
gimp-1.2.3-20.9.el3.i386.rpm
gimp-devel-1.2.3-20.9.el3.i386.rpm
gimp-perl-1.2.3-20.9.el3.i386.rpm
   x86_64:
gimp-1.2.3-20.9.el3.x86_64.rpm
gimp-devel-1.2.3-20.9.el3.x86_64.rpm
gimp-perl-1.2.3-20.9.el3.x86_64.rpm

SL 4.x

   SRPMS:
gimp-2.0.5-7.0.7.el4.src.rpm
   i386:
gimp-2.0.5-7.0.7.el4.i386.rpm
gimp-devel-2.0.5-7.0.7.el4.i386.rpm
   x86_64:
gimp-2.0.5-7.0.7.el4.x86_64.rpm
gimp-devel-2.0.5-7.0.7.el4.x86_64.rpm

SL 5.x

   SRPMS:
gimp-2.2.13-2.0.7.el5.src.rpm
   i386:
gimp-2.2.13-2.0.7.el5.i386.rpm
gimp-devel-2.2.13-2.0.7.el5.i386.rpm
gimp-libs-2.2.13-2.0.7.el5.i386.rpm
   x86_64:
gimp-2.2.13-2.0.7.el5.x86_64.rpm
gimp-devel-2.2.13-2.0.7.el5.i386.rpm
gimp-devel-2.2.13-2.0.7.el5.x86_64.rpm
gimp-libs-2.2.13-2.0.7.el5.i386.rpm
gimp-libs-2.2.13-2.0.7.el5.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2006-4519 gimp SL5.x, SL4.x, SL3,x i386/x86_64

Moderate: gimp security update

Summary

Date:         Wed, 26 Sep 2007 14:40:30 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for gimp on SL5.x, SL4.x, SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis:	Moderate: gimp security updateIssue date:	RHSA-2007:0513-01CVE Names:	CVE-2006-4519 CVE-2007-2949 CVE-2007-3741Multiple integer overflow and input validation flaws were found in TheGIMP's image loaders.  An attacker could create a carefully crafted imagefile that could cause The GIMP to crash or possibly execute arbitrary codeif the file was opened by a victim. (CVE-2006-4519, CVE-2007-2949,CVE-2007-3741)SL 3.0.x   SRPMS:gimp-1.2.3-20.9.el3.src.rpm   i386:gimp-1.2.3-20.9.el3.i386.rpmgimp-devel-1.2.3-20.9.el3.i386.rpmgimp-perl-1.2.3-20.9.el3.i386.rpm   x86_64:gimp-1.2.3-20.9.el3.x86_64.rpmgimp-devel-1.2.3-20.9.el3.x86_64.rpmgimp-perl-1.2.3-20.9.el3.x86_64.rpmSL 4.x   SRPMS:gimp-2.0.5-7.0.7.el4.src.rpm   i386:gimp-2.0.5-7.0.7.el4.i386.rpmgimp-devel-2.0.5-7.0.7.el4.i386.rpm   x86_64:gimp-2.0.5-7.0.7.el4.x86_64.rpmgimp-devel-2.0.5-7.0.7.el4.x86_64.rpmSL 5.x   SRPMS:gimp-2.2.13-2.0.7.el5.src.rpm   i386:gimp-2.2.13-2.0.7.el5.i386.rpmgimp-devel-2.2.13-2.0.7.el5.i386.rpmgimp-libs-2.2.13-2.0.7.el5.i386.rpm   x86_64:gimp-2.2.13-2.0.7.el5.x86_64.rpmgimp-devel-2.2.13-2.0.7.el5.i386.rpmgimp-devel-2.2.13-2.0.7.el5.x86_64.rpmgimp-libs-2.2.13-2.0.7.el5.i386.rpmgimp-libs-2.2.13-2.0.7.el5.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News