CVE-2007-3126

Summary

CVECVE-2007-3126
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2007-06-08 00:30:00 UTC
Updated2022-02-07 17:28:00 UTC
DescriptionGimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.

Risk And Classification

Problem Types: NVD-CWE-noinfo

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Gimp Gimp All All All All
Application The Gimp Team Gimp 2.3.14 All All All
Application The Gimp Team Gimp 2.3.14 All All All

References

ReferenceSourceLinkTags
SecurityFocus BUGTRAQ www.securityfocus.com
43453 OSVDB osvdb.org
Bug 773233 - CVE-2007-3126 - Gimp 2.3.14 allows context-dependent attackers... (323ecb73) · Commits · GNOME / GIMP · GitLab CONFIRM git.gnome.org
Bug 778604 – CVE-2007-3126 - Gimp 2.3.14 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, CONFIRM bugzilla.gnome.org
IBM X-Force Exchange XF exchange.xforce.ibmcloud.com
GIMP 2.8.22 Released - GIMP CONFIRM www.gimp.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

OrganizationPublishedContributorStatement
Mandriva2007-09-17Vincent DanenMandriva does not consider a user-assisted crash of an end-user application such as the GIMP to be a security issue.
Red Hat2007-06-29Joshua BressersRed Hat does not consider a user-assisted crash of a user application such as GIMP to be a security issue.
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report