VulnerabilityModified
CVE-2006-4519
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
MEDIUM 6.8EPSS 5.60%
Does this matter?
Lower severity and a low EPSS score (5.60%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 5.60% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- gimp/gimp
- Source
- cve@mitre.org
References
- http://bugzilla.gnome.org/show_bug.cgi?id=451379Issue Tracking, Third Party Advisory
- http://developer.gimp.org/NEWS-2.2Broken Link
- http://issues.foresightlinux.org/browse/FL-457Broken Link
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=551Broken Link
- http://osvdb.org/42139Broken Link
- http://osvdb.org/42140Broken Link
- http://osvdb.org/42141Broken Link
- http://osvdb.org/42142Broken Link
- http://osvdb.org/42143Broken Link
- http://osvdb.org/42144Broken Link
- http://osvdb.org/42145Broken Link
- http://secunia.com/advisories/26132Broken Link
- http://secunia.com/advisories/26215Broken Link
- http://secunia.com/advisories/26240Broken Link
- http://secunia.com/advisories/26575Broken Link
- http://secunia.com/advisories/26939Broken Link
- http://security.gentoo.org/glsa/glsa-200707-09.xmlThird Party Advisory
- http://www.debian.org/security/2007/dsa-1335Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:170Broken Link
- http://www.redhat.com/support/errata/RHSA-2007-0513.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/475257/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/24835Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018349Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-494-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/2471Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35308Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10842Tool Signature
- http://bugzilla.gnome.org/show_bug.cgi?id=451379Issue Tracking, Third Party Advisory
- http://developer.gimp.org/NEWS-2.2Broken Link
- http://issues.foresightlinux.org/browse/FL-457Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.