fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gimp | Aug 30, 2017 | Jul 12, 2012 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jul 12, 2012 |
| Oracle Solaris | — | Upgrade image/editor/gimp to version 2.6.10-0.175.0.11.0.3.0 on Solaris 11.0 | May 29, 2017 | Jul 12, 2012 |
| Suse | — | Upgrade gimp-plugins-pythonUpgrade gimp-develUpgrade gimp-langUpgrade gimpUpgrade libgimp-2_0-0Upgrade libgimpui-2_0-0 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gimp | Nov 8, 2024 | Jul 12, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub