TUCoPS :: Linux :: Gentoo :: tb11778.htm

GIMP: Multiple integer overflows
GIMP: Multiple integer overflows
GIMP: Multiple integer overflows




--PNTmBPCT7hxwcZjr
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200707-09
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/ 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: GIMP: Multiple integer overflows
      Date: July 25, 2007
      Bugs: #182047
        ID: 200707-09

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
=======
Multiple vulnerabilities have been discovered in GIMP, allowing for the
remote execution of arbitrary code.

Background
=========
GIMP is the GNU Image Manipulation Program.

Affected packages
================
    -------------------------------------------------------------------
     Package         /  Vulnerable  /                       Unaffected
    -------------------------------------------------------------------
  1  media-gfx/gimp      < 2.2.16                            >= 2.2.16

Description
==========
Sean Larsson from iDefense Labs discovered multiple integer overflows
in various GIMP plugins (CVE-2006-4519). Stefan Cornelius from Secunia
Research discovered an integer overflow in the
seek_to_and_unpack_pixeldata() function when processing PSD files
(CVE-2007-2949).

Impact
=====
A remote attacker could entice a user to open a specially crafted image
file, possibly resulting in the execution of arbitrary code with the
privileges of the user running GIMP.

Workaround
=========
There is no known workaround at this time.

Resolution
=========
All GIMP users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-gfx/gimp-2.2.16"

References
=========
  [ 1 ] CVE-2006-4519
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4519 
  [ 2 ] CVE-2007-2949
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2949 

Availability
===========
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200707-09.xml 

Concerns?
========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at 
http://bugs.gentoo.org. 

License
======
Copyright 2007 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5 

--PNTmBPCT7hxwcZjr
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iQEVAwUBRqejIDvRww8BFPxFAQKiSQf8CTgyUqPJ2/7s4LMYt63ZmQTRNwHMknzH
DEVWs9XQVk6wzF8aDHmInVYAIcKavdq+nnKAllN7kMLSVbDXt4QYRoDmm7xyr3zz
rKhGoFL3jEqC5X0FfP49cYl7n3z3w6BiHOsccCjU/HkJ8H50jQHtPHnYEk/v7hCt
vBA5DYGgXq/iwPZTkwe6aJb6TPI8jZ0vbHKpeUdV4b86PY1OjYmjrGt3bbHoNPN/
lVC7io596/UToxW8bFu654A2br12i4myFqjojFw3zW5VMRAECda+jfgj3IG6TfIn
hXVHFNOX/oKHUSS6DoeqnOvBd68bJKzNAlFEooT45sR1fem74guASw==JmOX
-----END PGP SIGNATURE-----

--PNTmBPCT7hxwcZjr--

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH