[GIMP] Multiple Integer Overflow Vulnerabilities (CVE-2006-4519)

Bug #125237 reported by disabled.user
256
Affects Status Importance Assigned to Milestone
The Gimp
Fix Released
High
gimp (Ubuntu)
Fix Released
Medium
Kees Cook

Bug Description

Binary package hint: gimp

From:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=551

"iDefense has confirmed that version 2.2.15 of The GIMP is vulnerable on both Linux and Windows platforms. It is suspected that all previous versions of the GIMP are also affected."

"Remote exploitation of multiple integer overflow vulnerabilities in several of the image loader plug-ins included with distributions of 'The GIMP' allow attackers to crash The GIMP or potentially execute arbitrary code with the privileges of the user."

"Exploitation allows attackers to execute arbitrary code in the context of the user opening a malicious image file. In order to be successful, the attacker must convince the victim into opening a maliciously crafted image with The GIMP. "

"The GIMP maintainers have released version 2.2.16 to address these vulnerabilities. For more information, consult the following URL.
http://developer.gimp.org/NEWS-2.2 "

Please provide fixed packages as soon as possible. Thanks.

CVE References

Changed in gimp:
status: Unknown → Fix Released
Revision history for this message
disabled.user (disabled.user-deactivatedaccount) wrote :

Bug report can be closed for Ubuntu since updated packages for the stable releases are available (USN-494-1).

(http://www.ubuntu.com/usn/usn-494-1)

Kees Cook (kees)
Changed in gimp:
assignee: nobody → keescook
importance: Undecided → Medium
status: New → Fix Released
Changed in gimp:
importance: Unknown → High
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.