CVE-2006-3404
published 2006-07-06CVE-2006-3404: Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service…
PriorityP427medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
5.04%
91.4th percentile
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.2.11-3.1 (bookworm) | gimp 2.2.11-3.1 (bookworm) |
| gimp | gimp | < 2.2.12 | 2.2.12 |
| gimp | gimp | >= 0 < 2.2.11-3.1 | 2.2.11-3.1 |
| gimp | gimp | >= 0 < 2.2.11-3.1 | 2.2.11-3.1 |
| gimp | gimp | >= 0 < 2.2.11-3.1 | 2.2.11-3.1 |
| gimp | gimp | >= 0 < 2.2.11-3.1 | 2.2.11-3.1 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
gimp vulnerability
vendor_ubuntu·2006-07-10
CVE-2006-3404 gimp vulnerability
Title: gimp vulnerability
Summary: gimp vulnerability
Henning Makholm discovered that gimp did not sufficiently validate the
'num_axes' parameter in XCF files. By tricking a user into opening a
specially crafted XCF file with Gimp, an attacker could exploit this
to execute arbitrary code with the user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
security flaw
vendor_redhat·2006-07-06·CVSS 5.1
CVE-2006-3404 [MEDIUM] security flaw
security flaw
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
Debian
CVE-2006-3404: gimp - Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp b...
vendor_debian·2006·CVSS 5.1
CVE-2006-3404 [MEDIUM] CVE-2006-3404: gimp - Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp b...
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
Scope: local
bookworm: resolved (fixed in 2.2.11-3.1)
bullseye: resolved (fixed in 2.2.11-3.1)
forky: resolved (fixed in 2.2.11-3.1)
sid: resolved (fixed in 2.2.11-3.1)
trixie: resolved (fixed in 2.2.11-3.1)
GHSA
GHSA-g4v5-f3x8-hh5w: Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load
ghsa_unreviewed·2022-05-01
CVE-2006-3404 [MEDIUM] CWE-120 GHSA-g4v5-f3x8-hh5w: Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
OSV
CVE-2006-3404: Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load
osv·2006-07-06·CVSS 5.1
CVE-2006-3404 [MEDIUM] CVE-2006-3404: Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
No detection rules found.
Bugzilla
CVE-2006-3404 security flaw
bugzilla·2018-08-16·CVSS 5.1
CVE-2006-3404 [MEDIUM] CVE-2006-3404 security flaw
CVE-2006-3404 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
Bugzilla
CVE-2006-3404 gimp xcf buffer overflow
bugzilla·2006-07-10·CVSS 5.1
CVE-2006-3404 [MEDIUM] CVE-2006-3404 gimp xcf buffer overflow
CVE-2006-3404 gimp xcf buffer overflow
gimp xcf buffer overflow
Henning Makholm discovered a buffer overflow bug in gimp's XCF loader.
It is possible to overflow a static buffer with arbitrary data, which
could likely result in arbitrary code execution.
The upstream bug contains the patch:
http://bugzilla.gnome.org/show_bug.cgi?id=346742
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
I'm not sure if this issue affects RHEL2.1 or not. I can't find the source in
question, but I'm also not terribly familiar with the source of the XCF format.
---
gimp-1.2.x (what is in RHEL2.1 and RHEL3) doesn't seem to store or load vector
information in XCF files. I've contacted Henning Makholm (who provided the patch
upstream) about a testcase file.
---
gimp-1.2.x (what
Bugzilla
CVE-2006-3404 gimp xcf buffer overflow
bugzilla·2006-07-10·CVSS 5.1
CVE-2006-3404 [MEDIUM] CVE-2006-3404 gimp xcf buffer overflow
CVE-2006-3404 gimp xcf buffer overflow
+++ This bug was initially created as a clone of Bug #198269 +++
gimp xcf buffer overflow
Henning Makholm discovered a buffer overflow bug in gimp's XCF loader.
It is possible to overflow a static buffer with arbitrary data, which
could likely result in arbitrary code execution.
The upstream bug contains the patch:
http://bugzilla.gnome.org/show_bug.cgi?id=346742
Discussion:
This issue should also affect FC4
---
Created attachment 132207
gimp-2.2.12-gcc4.patch
updated gcc4 patch ...
---
gimp-2.2.12 has already been built for FC4, FC5 and Rawhide and waits for
pushing. Jens, thanks for the updated patch but with 2.2.12 it is no longer
necessary as upstream just uses -mmmx, -msse and so on to build these asm source
files.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=377049http://bugzilla.gnome.org/show_bug.cgi?id=346742http://secunia.com/advisories/20976http://secunia.com/advisories/20979http://secunia.com/advisories/21069http://secunia.com/advisories/21104http://secunia.com/advisories/21170http://secunia.com/advisories/21182http://secunia.com/advisories/21198http://secunia.com/advisories/21459http://secunia.com/advisories/23044http://security.gentoo.org/glsa/glsa-200607-08.xmlhttp://securitytracker.com/id?1016527http://sunsolve.sun.com/search/document.do?assetkey=1-26-102720-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200070-1http://www.debian.org/security/2006/dsa-1116http://www.mandriva.com/security/advisories?name=MDKSA-2006:127http://www.novell.com/linux/security/advisories/2006_19_sr.htmlhttp://www.osvdb.org/27037http://www.redhat.com/support/errata/RHSA-2006-0598.htmlhttp://www.securityfocus.com/archive/1/440987/100/0/threadedhttp://www.securityfocus.com/archive/1/441012/100/0/threadedhttp://www.securityfocus.com/archive/1/441030/100/0/threadedhttp://www.securityfocus.com/bid/18877http://www.ubuntu.com/usn/usn-312-1http://www.vupen.com/english/advisories/2006/2703http://www.vupen.com/english/advisories/2006/4634https://exchange.xforce.ibmcloud.com/vulnerabilities/27687https://issues.rpath.com/browse/RPL-522https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11259https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5908http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=377049http://bugzilla.gnome.org/show_bug.cgi?id=346742http://secunia.com/advisories/20976http://secunia.com/advisories/20979http://secunia.com/advisories/21069http://secunia.com/advisories/21104http://secunia.com/advisories/21170http://secunia.com/advisories/21182http://secunia.com/advisories/21198http://secunia.com/advisories/21459http://secunia.com/advisories/23044http://security.gentoo.org/glsa/glsa-200607-08.xmlhttp://securitytracker.com/id?1016527http://sunsolve.sun.com/search/document.do?assetkey=1-26-102720-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200070-1http://www.debian.org/security/2006/dsa-1116http://www.mandriva.com/security/advisories?name=MDKSA-2006:127http://www.novell.com/linux/security/advisories/2006_19_sr.htmlhttp://www.osvdb.org/27037http://www.redhat.com/support/errata/RHSA-2006-0598.htmlhttp://www.securityfocus.com/archive/1/440987/100/0/threadedhttp://www.securityfocus.com/archive/1/441012/100/0/threadedhttp://www.securityfocus.com/archive/1/441030/100/0/threadedhttp://www.securityfocus.com/bid/18877http://www.ubuntu.com/usn/usn-312-1http://www.vupen.com/english/advisories/2006/2703http://www.vupen.com/english/advisories/2006/4634https://exchange.xforce.ibmcloud.com/vulnerabilities/27687https://issues.rpath.com/browse/RPL-522https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11259https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5908
2006-07-06
Published