Back

CRITICAL

gimp: predictable temporary file name in test-xcf.c unit test

Published Jun 24, 2018

Description

GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.

Affected products

Remediation

Red Hat statement

This issue did affect the versions of gimp as shipped with Red Hat Enterprise Linux 7. However, as this is an issue in a unit test, it is not a problem if you are using the precompiled gimp package. This is only a problem if you recompile gimp using the src.rpm/SPEC file. Even then it's only a problem if you do not make use of isolating build tools like mock, but instead use rpmbuild directly.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 24, 2018
Updated Aug 5, 2024
Reserved Jun 24, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 21, 2018