An issue was discovered in GEGL through 0.3.32. The gegl_buffer_iterate_read_simple function in buffer/gegl-buffer-access.c allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via a malformed PPM file, related to improper restrictions on memory allocation in the ppm_load_read_header function in operations/external/ppm-load.c.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gegl | Jul 30, 2024 | Apr 16, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade gegl | Sep 16, 2021 | Apr 16, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gegl | Nov 19, 2019 | Apr 16, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 16, 2018 |
| Suse | — | Upgrade typelib-1_0-gegl-0_4Upgrade gegl-0_4-langUpgrade typelib-1_0-gegl-0_3Upgrade gegl-0_4Upgrade libgegl-0_3-0Upgrade gegl-0_3-langUpgrade gegl-develUpgrade libgegl-0_4-0Upgrade geglUpgrade gegl-0_3Upgrade gegl-doc | May 20, 2018 | Apr 16, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub