GIMP CVE-2012-3402 Buffer Overflow Vulnerability
BID:55103
Info
GIMP CVE-2012-3402 Buffer Overflow Vulnerability
| Bugtraq ID: | 55103 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-3402 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 10 2012 12:00AM |
| Updated: | Feb 19 2013 07:42AM |
| Credit: | Red Hat |
| Vulnerable: |
RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 GIMP GIMP 2.6.7 GIMP GIMP 2.6.6 GIMP GIMP 2.4.6 GIMP GIMP 2.3.14 GIMP GIMP 2.3.10 GIMP GIMP 2.3.9 GIMP GIMP 2.2.17 GIMP GIMP 2.2.16 GIMP GIMP 2.2.15 GIMP GIMP 2.2.14 GIMP GIMP 2.2.12 GIMP GIMP 2.2.11 GIMP GIMP 2.2.8 GIMP GIMP 2.2.6 GIMP GIMP 2.2.4 GIMP GIMP 2.8.0 GIMP GIMP 2.6.12 GIMP GIMP 2.6.11 GIMP GIMP 2.6.11 Gentoo Linux Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 |
| Not Vulnerable: | |
Discussion
GIMP CVE-2012-3402 Buffer Overflow Vulnerability
GIMP is prone to a remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
GIMP is prone to a remote buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
GIMP CVE-2012-3402 Buffer Overflow Vulnerability
Currently we are not aware of any publicly available exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently we are not aware of any publicly available exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
GIMP CVE-2012-3402 Buffer Overflow Vulnerability
Solution:
A vendor patch is available. Please see the references for more information.
Solution:
A vendor patch is available. Please see the references for more information.