bugs.debian.org
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497 CVE-2010-4543
GIMP 2.6.7 - Multiple File Plugins Remote Stack Buffer Overflow Vulnerabilities
Record summary
CVE-2010-4543 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGIMP 2.6.7 - Multiple File Plugins Remote Stack Buffer Overflow VulnerabilitiesExploitDB exploitby non customersNot analyzed1 file
References
Showing 12 of 23SUSE-SR:2011:005Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html [oss-security] 20110103 CVE request for buffer overflows in gimpmailing list
http://openwall.com/lists/oss-security/2011/01/03/2 [oss-security] 20110104 Re: CVE request for buffer overflows in gimpmailing list
http://openwall.com/lists/oss-security/2011/01/04/7 70284vdb entry
http://osvdb.org/70284 42771Third-party advisory
http://secunia.com/advisories/42771 44750Third-party advisory
http://secunia.com/advisories/44750 48236Third-party advisory
http://secunia.com/advisories/48236 50737Third-party advisory
http://secunia.com/advisories/50737 GLSA-201209-23Vendor advisory
http://security.gentoo.org/glsa/glsa-201209-23.xml DSA-2426Vendor advisory
http://www.debian.org/security/2012/dsa-2426 MDVSA-2011:103Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2011:103