Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gimp | Aug 30, 2017 | Dec 17, 2012 |
| Centos_linux | — | Upgrade gimpUpgrade gimp-devel-toolsUpgrade gimp-develUpgrade gimp-help-browserUpgrade gimp-libs | Dec 1, 2016 | Dec 17, 2012 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Dec 18, 2012 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Dec 17, 2012 |
| Oracle_linux | — | Upgrade gimp-help-browserUpgrade gimpUpgrade gimp-devel-toolsUpgrade gimp-libsUpgrade gimp-devel | Oct 16, 2024 | Dec 18, 2012 |
| Suse | — | Upgrade libgimp-2_0-0Upgrade libgimpui-2_0-0Upgrade gimp-develUpgrade gimp-langUpgrade gimp-plugins-pythonUpgrade gimp | Dec 12, 2013 | Jul 9, 2013 |
| Ubuntu | — | Upgrade gimp | Nov 8, 2024 | Dec 18, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub