Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gimp-develUpgrade gimpUpgrade gimp-libs | Dec 1, 2016 | Nov 13, 2009 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Nov 13, 2009 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Nov 13, 2009 |
| Oracle_linux | — | Upgrade gimp-libsUpgrade gimp-develUpgrade gimp | Oct 16, 2024 | Nov 13, 2009 |
| Suse | — | Upgrade gimp-develUpgrade gimp-langUpgrade gimpUpgrade gimp-plugins-python | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gimp | Nov 8, 2024 | Nov 13, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub