7.5
CVSSv2

CVE-2012-4433

Published: 18/11/2012 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gegl gegl 0.2.0

Vendor Advisories

Synopsis Moderate: gegl security update Type/Severity Security Advisory: Moderate Topic Updated gegl packages that fix one security issue are now available forRed Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerability Scoring ...
Debian Bug report logs - #692435 gegl: CVE-2012-4433 - Integer overflow, leading to heap-based buffer overflow by parsing PPM image headers Package: gegl; Maintainer for gegl is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for gegl is src:gegl (PTS, buildd, popcon) Reported by: Luciano Bel ...