Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 11.04 USN-1214-1 Important GIMP Code Execution Vulnerability

Ubuntu Large Esm H500
GIMP could be made to run programs as your login if it opened a specially crafted GIF file.
=========================================================================Ubuntu Security Notice USN-1214-1
September 22, 2011

gimp vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

GIMP could be made to run programs as your login if it opened a
specially crafted GIF file.

Software Description:
- gimp: The GNU Image Manipulation Program

Details:

Tomas Hoger discovered that GIMP incorrectly handled malformed LZW streams.
If a user were tricked into opening a specially crafted GIF image file, an
attacker could cause GIMP to crash, or possibly execute arbitrary code with
the user's privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  gimp                            2.6.11-1ubuntu6.2

Ubuntu 10.10:
  gimp                            2.6.10-1ubuntu3.4

Ubuntu 10.04 LTS:
  gimp                            2.6.8-2ubuntu1.4

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-1214-1
  CVE-2011-2896

Package Information:
  https://launchpad.net/ubuntu/+source/gimp/2.6.11-1ubuntu6.2
  https://launchpad.net/ubuntu/+source/gimp/2.6.10-1ubuntu3.4
  https://launchpad.net/ubuntu/+source/gimp/2.6.8-2ubuntu1.4


Ubuntu 11.04 USN-1214-1 Important GIMP Code Execution Vulnerability

ubuntu
Calendar Grey September 22, 2011
Dist Ubuntu Esm H88
A critical vulnerability in GIMP on Ubuntu systems poses major risks. Malicious files can trigger exploits, compromising user data and system integrity
GIMP could be made to run programs as your login if it opened a specially crafted GIF file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: gimp 2.6.11-1ubuntu6.2 Ubuntu 10.10: gimp 2.6.10-1ubuntu3.4 Ubuntu 10.04 LTS: gimp 2.6.8-2ubuntu1.4 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1214-1

CVE-2011-2896

Severity
important
Lowest
Low
Medium
High
Critical

September 22, 2011

Package Information

https://launchpad.net/ubuntu/+source/gimp/2.6.11-1ubuntu6.2 https://launchpad.net/ubuntu/+source/gimp/2.6.10-1ubuntu3.4 https://launchpad.net/ubuntu/+source/gimp/2.6.8-2ubuntu1.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here