6.8
CVSSv2

CVE-2012-3403

Published: 25/08/2012 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and previous versions allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted KiSS palette file, which triggers an "invalid free."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gimp gimp

Vendor Advisories

Debian Bug report logs - #685397 gimp: CVE-2012-3403 Package: gimp; Maintainer for gimp is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for gimp is src:gimp (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 20 Aug 2012 13:09:05 UTC Severity: grave T ...
GIMP could be made to crash or run programs as your login if it opened a specially crafted file ...
Synopsis Moderate: gimp security update Type/Severity Security Advisory: Moderate Topic Updated gimp packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Sco ...
Synopsis Moderate: gimp security update Type/Severity Security Advisory: Moderate Topic Updated gimp packages that fix three security issues are now available forRed Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Scorin ...
Murray McAllister discovered multiple integer and buffer overflows in the XWD plugin in Gimp, which can result in the execution of arbitrary code For the oldstable distribution (squeeze), these problems have been fixed in version 2610-1+squeeze4 This update also fixes CVE-2012-3403, CVE-2012-3481 and CVE-2012-5576 For the stable distribution ( ...