GIMP PCX Image Parsing Heap Buffer Overflow Vulnerability
BID:48057
Info
GIMP PCX Image Parsing Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 48057 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-1178 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2011 12:00AM |
| Updated: | Apr 01 2013 01:27PM |
| Credit: | Red Hat |
| Vulnerable: |
RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 GIMP GIMP 2.6.7 GIMP GIMP 2.6.6 GIMP GIMP 2.4.6 GIMP GIMP 2.3.14 GIMP GIMP 2.3.10 GIMP GIMP 2.3.9 GIMP GIMP 2.2.17 GIMP GIMP 2.2.16 GIMP GIMP 2.2.15 GIMP GIMP 2.2.14 GIMP GIMP 2.2.12 GIMP GIMP 2.2.11 GIMP GIMP 2.2.8 GIMP GIMP 2.2.6 GIMP GIMP 2.2.4 GIMP GIMP 1.2.5 GIMP GIMP 2.6.11 Gentoo Linux Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 |
| Not Vulnerable: | |
Discussion
GIMP PCX Image Parsing Heap Buffer Overflow Vulnerability
GIMP is prone to an heap-based buffer-overflow vulnerability because of an integer-overflow error in the PCX image file plug-in.
Successfully exploiting this issue may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
GIMP is prone to an heap-based buffer-overflow vulnerability because of an integer-overflow error in the PCX image file plug-in.
Successfully exploiting this issue may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
GIMP PCX Image Parsing Heap Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GIMP PCX Image Parsing Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2009.0
Mandriva Linux Mandrake 2009.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva gimp-2.4.7-1.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva gimp-python-2.4.7-1.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64gimp2.0-devel-2.4.7-1.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64gimp2.0_0-2.4.7-1.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva gimp-2.4.7-1.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva gimp-python-2.4.7-1.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libgimp2.0-devel-2.4.7-1.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libgimp2.0_0-2.4.7-1.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2009.0
-
Mandriva gimp-2.4.7-1.3mdv2009.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva gimp-python-2.4.7-1.3mdv2009.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libgimp2.0-devel-2.4.7-1.3mdv2009.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libgimp2.0_0-2.4.7-1.3mdv2009.0.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva gimp-2.4.7-1.3mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva gimp-python-2.4.7-1.3mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64gimp2.0-devel-2.4.7-1.3mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64gimp2.0_0-2.4.7-1.3mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
GIMP PCX Image Parsing Heap Buffer Overflow Vulnerability
References:
References:
- GIMP Homepage (GIMP)
- ASA-2011-162 gimp security update (RHSA-2011-0838) (Avaya)