Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted KiSS palette file, which triggers an "invalid free."
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gimp-devel-toolsUpgrade gimpUpgrade gimp-help-browserUpgrade gimp-libsUpgrade gimp-devel | Dec 1, 2016 | Aug 25, 2012 |
| Debian | — | Upgrade gimp | Jul 30, 2024 | Aug 25, 2012 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Aug 25, 2012 |
| Oracle Solaris | — | Upgrade image/editor/gimp to version 2.6.10-0.175.1.4.0.1.2 on Solaris 11.1 | May 29, 2017 | Aug 25, 2012 |
| Oracle_linux | — | Upgrade gimp-develUpgrade gimp-libsUpgrade gimp | Oct 16, 2024 | Aug 25, 2012 |
| Suse | — | Upgrade gimp-develUpgrade gimp-langUpgrade gimp-plugins-pythonUpgrade gimp | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gimp | Nov 8, 2024 | Aug 25, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub