Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gimp-develUpgrade gimp-libsUpgrade gimp | Dec 1, 2016 | Nov 13, 2009 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Nov 13, 2009 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Nov 13, 2009 |
| Oracle_linux | — | Upgrade gimpUpgrade gimp-develUpgrade gimp-libs | Oct 16, 2024 | Nov 13, 2009 |
| Suse | — | Upgrade gimpUpgrade gimp-plugins-pythonUpgrade gimp-develUpgrade gimp-lang | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gimp | Nov 8, 2024 | Nov 13, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub