MEDIUM
GIMP multiple image loader integer overflows
Published Jul 10, 2007
6.8
MEDIUMCVSS 2.0
EPSS 5.60%
Description
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
Affected products
No data.
No data.
Red Hat Enterprise Linux 2.1
gimp-1:1.2.1-7.8.el2_1
Fixed · RHSA-2007:0513
Red Hat Enterprise Linux 3
gimp-1:1.2.3-20.9.el3
Fixed · RHSA-2007:0513
Red Hat Enterprise Linux 4
gimp-1:2.0.5-7.0.7.el4
Fixed · RHSA-2007:0513
Red Hat Enterprise Linux 5
gimp-2:2.2.13-2.0.7.el5
Fixed · RHSA-2007:0513
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | gimp-1:1.2.1-7.8.el2_1 | Fixed | RHSA-2007:0513 |
| Red Hat Enterprise Linux 3 | gimp-1:1.2.3-20.9.el3 | Fixed | RHSA-2007:0513 |
| Red Hat Enterprise Linux 4 | gimp-1:2.0.5-7.0.7.el4 | Fixed | RHSA-2007:0513 |
| Red Hat Enterprise Linux 5 | gimp-2:2.2.13-2.0.7.el5 | Fixed | RHSA-2007:0513 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (32)
- http://bugzilla.gnome.org/show_bug.cgi?id=451379 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- http://developer.gimp.org/NEWS-2.2 x_refsource_CONFIRMBroken Link
- http://issues.foresightlinux.org/browse/FL-457 x_refsource_CONFIRMBroken Link
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=551 third-party-advisoryx_refsource_IDEFENSEBroken Link
- http://osvdb.org/42139 vdb-entryx_refsource_OSVDBBroken Link
- http://osvdb.org/42140 vdb-entryx_refsource_OSVDBBroken Link
- http://osvdb.org/42141 vdb-entryx_refsource_OSVDBBroken Link
- http://osvdb.org/42142 vdb-entryx_refsource_OSVDBBroken Link
- http://osvdb.org/42143 vdb-entryx_refsource_OSVDBBroken Link
- http://osvdb.org/42144 vdb-entryx_refsource_OSVDBBroken Link
- http://osvdb.org/42145 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/26132 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26215 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26240 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26575 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/26939 third-party-advisoryx_refsource_SECUNIABroken Link
- http://security.gentoo.org/glsa/glsa-200707-09.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.debian.org/security/2007/dsa-1335 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:170 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.redhat.com/support/errata/RHSA-2007-0513.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/archive/1/475257/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/24835 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1018349 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-494-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2007/2471 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2006-4519 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=247565 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-4507 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35308 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2006-4519
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10842 vdb-entrysignaturex_refsource_OVALTool Signature
- https://www.cve.org/CVERecord?id=CVE-2006-4519
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 10, 2007
Updated Aug 7, 2024
Reserved Aug 31, 2006
Link CVE-2006-4519
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-4507 Assigner mitre
Published Jul 10, 2007
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-4507