7.5
CVSSv2

CVE-2012-5576

Published: 18/12/2012 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gimp gimp

Vendor Advisories

Synopsis Moderate: gimp security update Type/Severity Security Advisory: Moderate Topic Updated gimp packages that fix three security issues are now available forRed Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability ...
Debian Bug report logs - #693977 gimp: CVE-2012-5576: memory corruption vulnerability affecting 282 Package: gimp; Maintainer for gimp is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for gimp is src:gimp (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Thu, 22 ...
GIMP could be made to crash or run programs as your login if it opened a specially crafted file ...
Murray McAllister discovered multiple integer and buffer overflows in the XWD plugin in Gimp, which can result in the execution of arbitrary code For the oldstable distribution (squeeze), these problems have been fixed in version 2610-1+squeeze4 This update also fixes CVE-2012-3403, CVE-2012-3481 and CVE-2012-5576 For the stable distribution ( ...