fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gimp | Aug 30, 2017 | Jul 12, 2012 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jul 12, 2012 |
| Oracle Solaris | — | Upgrade image/editor/gimp to version 2.6.10-0.175.0.11.0.3.0 on Solaris 11.0 | May 29, 2017 | Jul 12, 2012 |
| Suse | — | Upgrade libgimpui-2_0-0-debuginfo-x86Upgrade libgimpui-2_0-0Upgrade gimp-langUpgrade libgimp-2_0-0Upgrade gimp-help-browserUpgrade libgimp-2_0-0-debuginfo-x86Upgrade libgimp-2_0-0-debuginfoUpgrade gimpUpgrade gimp-help-browser-debuginfoUpgrade libgimp-2_0-0-32bitUpgrade gimp-develUpgrade gimp-debuginfoUpgrade libgimpui-2_0-0-debuginfoUpgrade libgimp-2_0-0-debuginfo-32bitUpgrade gimp-devel-debuginfoUpgrade libgimpui-2_0-0-32bitUpgrade gimp-plugins-pythonUpgrade gimp-debugsourceUpgrade libgimp-2_0-0-x86Upgrade gimp-branding-upstreamUpgrade libgimpui-2_0-0-debuginfo-32bitUpgrade gimp-plugins-python-debuginfoUpgrade libgimpui-2_0-0-x86 | Feb 17, 2015 | Jul 12, 2012 |
| Ubuntu | — | Upgrade gimp | Nov 8, 2024 | Jul 12, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub