Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 11.04 USN-1214-1 Important GIMP Code Execution Vulnerability

ubuntu
Calendar Grey September 22, 2011
Scroller Ubuntu
A critical vulnerability in GIMP on Ubuntu systems poses major risks. Malicious files can trigger exploits, compromising user data and system integrity
GIMP could be made to run programs as your login if it opened a specially crafted GIF file.

Summary

GIMP could be made to run programs as your login if it opened a

specially crafted GIF file.

Software Description:

- gimp: The GNU Image Manipulation Program

Details:

Tomas Hoger discovered that GIMP incorrectly handled malformed LZW streams.

If a user were tricked into opening a specially crafted GIF image file, an

attacker could cause GIMP to crash, or possibly execute arbitrary code with

the user's privileges.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  gimp                            2.6.11-1ubuntu6.2

Ubuntu 10.10:
  gimp                            2.6.10-1ubuntu3.4

Ubuntu 10.04 LTS:
  gimp                            2.6.8-2ubuntu1.4

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1214-1

CVE-2011-2896

Severity
important
Lowest
Low
Medium
High
Critical

September 22, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.