Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jul 6, 2006 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Jul 6, 2006 |
| Suse | — | Upgrade gimp-plugins-pythonUpgrade gimp-develUpgrade gimp-langUpgrade gimp | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gimpUpgrade libgimp2.0 | Nov 8, 2024 | Jul 6, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub