CVE-2006-4519
published 2007-07-10CVE-2006-4519: Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.60%
92.1th percentile
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.2.16-1 (bookworm) | gimp 2.2.16-1 (bookworm) |
| gimp | gimp | < 2.2.16 | 2.2.16 |
| gimp | gimp | >= 0 < 2.2.16-1 | 2.2.16-1 |
| gimp | gimp | >= 0 < 2.2.16-1 | 2.2.16-1 |
| gimp | gimp | >= 0 < 2.2.16-1 | 2.2.16-1 |
| gimp | gimp | >= 0 < 2.2.16-1 | 2.2.16-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g559-rf7h-66vc: Multiple integer overflows in the image loader plug-ins in GIMP before 2
ghsa_unreviewed·2022-05-01
CVE-2006-4519 [MEDIUM] CWE-190 GHSA-g559-rf7h-66vc: Multiple integer overflows in the image loader plug-ins in GIMP before 2
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
OSV
CVE-2006-4519: Multiple integer overflows in the image loader plug-ins in GIMP before 2
osv·2007-07-10·CVSS 6.8
CVE-2006-4519 [MEDIUM] CVE-2006-4519: Multiple integer overflows in the image loader plug-ins in GIMP before 2
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
Ubuntu
Gimp vulnerability
vendor_ubuntu·2007-08-02
CVE-2006-4519 Gimp vulnerability
Title: Gimp vulnerability
Summary: Gimp vulnerability
Sean Larsson discovered multiple integer overflows in Gimp. By tricking
a user into opening a specially crafted DICOM, PNM, PSD, PSP, RAS, XBM,
or XWD image, a remote attacker could exploit this to execute arbitrary
code with the user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
GIMP multiple image loader integer overflows
vendor_redhat·2007-07-09·CVSS 6.8
CVE-2006-4519 [MEDIUM] CWE-190 GIMP multiple image loader integer overflows
GIMP multiple image loader integer overflows
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
Debian
CVE-2006-4519: gimp - Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 al...
vendor_debian·2006·CVSS 6.8
CVE-2006-4519 [MEDIUM] CVE-2006-4519: gimp - Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 al...
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
Scope: local
bookworm: resolved (fixed in 2.2.16-1)
bullseye: resolved (fixed in 2.2.16-1)
forky: resolved (fixed in 2.2.16-1)
sid: resolved (fixed in 2.2.16-1)
trixie: resolved (fixed in 2.2.16-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4519 GIMP multiple image loader integer overflows
bugzilla·2007-07-10·CVSS 6.8
CVE-2006-4519 [MEDIUM] CVE-2006-4519 GIMP multiple image loader integer overflows
CVE-2006-4519 GIMP multiple image loader integer overflows
iDefense has reported several integer overflow flaws in GIMP. It is presumed
that these flaws could lead to arbitrary code execution if a victim opens a
malicious image file.
Discussion:
Reproducers for some of the problems can be found in one of the corresponding
upstream bugs: http://bugzilla.gnome.org/show_bug.cgi?id=453973
---
This was addressed via:
Red Hat Enterprise Linux version 2.1 (RHSA-2007:0513)
Red Hat Enterprise Linux version 3 (RHSA-2007:0513)
Red Hat Enterprise Linux version 4 (RHSA-2007:0513)
Red Hat Enterprise Linux version 5 (RHSA-2007:0513)
Bugzilla
CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [FC6]
bugzilla·2007-07-10·CVSS 6.8
CVE-2006-4519 [MEDIUM] CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [FC6]
CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
supposed to be fixed in gimp-2.2.16-1.fc6 which is in updates-testing
---
gimp-2.2.16-2.fc6
---
gimp-2.2.17-1.fc6
---
Nils, is this fixed in FEDORA-2007-627 (gimp-2.2.17-1.fc6)?
If yes, is there any reason for not closing this bug?
---
No, there isn't.
Bugzilla
CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [Fdevel]
bugzilla·2007-07-10·CVSS 6.8
CVE-2006-4519 [MEDIUM] CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [Fdevel]
CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
supposed to be fixed in gimp-2.2.16-1.fc8 which is built already, should hit
Rawhide with the next compose/push
---
regressions popped up, fixed in gimp-2.2.17-1.fc8, should hit Rawhide with the
next compose/push
Bugzilla
CVE-2006-4519 GIMP multiple image loader integer overflows [F7]
bugzilla·2007-07-10·CVSS 6.8
CVE-2006-4519 [MEDIUM] CVE-2006-4519 GIMP multiple image loader integer overflows [F7]
CVE-2006-4519 GIMP multiple image loader integer overflows [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
supposed to be fixed in gimp-2.2.16-1.fc7 which is in updates-testing
---
gimp-2.2.16-2.fc7
---
gimp-2.2.16-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
unpushed, the psd fixes cause a regression with images that contain zero
width/height layers
---
built gimp-2.2.17-1.fc7 and pushed
---
gimp-2.2.17-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
http://bugzilla.gnome.org/show_bug.cgi?id=451379http://developer.gimp.org/NEWS-2.2http://issues.foresightlinux.org/browse/FL-457http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=551http://osvdb.org/42139http://osvdb.org/42140http://osvdb.org/42141http://osvdb.org/42142http://osvdb.org/42143http://osvdb.org/42144http://osvdb.org/42145http://secunia.com/advisories/26132http://secunia.com/advisories/26215http://secunia.com/advisories/26240http://secunia.com/advisories/26575http://secunia.com/advisories/26939http://security.gentoo.org/glsa/glsa-200707-09.xmlhttp://www.debian.org/security/2007/dsa-1335http://www.mandriva.com/security/advisories?name=MDKSA-2007:170http://www.redhat.com/support/errata/RHSA-2007-0513.htmlhttp://www.securityfocus.com/archive/1/475257/100/0/threadedhttp://www.securityfocus.com/bid/24835http://www.securitytracker.com/id?1018349http://www.ubuntu.com/usn/usn-494-1http://www.vupen.com/english/advisories/2007/2471https://exchange.xforce.ibmcloud.com/vulnerabilities/35308https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10842http://bugzilla.gnome.org/show_bug.cgi?id=451379http://developer.gimp.org/NEWS-2.2http://issues.foresightlinux.org/browse/FL-457http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=551http://osvdb.org/42139http://osvdb.org/42140http://osvdb.org/42141http://osvdb.org/42142http://osvdb.org/42143http://osvdb.org/42144http://osvdb.org/42145http://secunia.com/advisories/26132http://secunia.com/advisories/26215http://secunia.com/advisories/26240http://secunia.com/advisories/26575http://secunia.com/advisories/26939http://security.gentoo.org/glsa/glsa-200707-09.xmlhttp://www.debian.org/security/2007/dsa-1335http://www.mandriva.com/security/advisories?name=MDKSA-2007:170http://www.redhat.com/support/errata/RHSA-2007-0513.htmlhttp://www.securityfocus.com/archive/1/475257/100/0/threadedhttp://www.securityfocus.com/bid/24835http://www.securitytracker.com/id?1018349http://www.ubuntu.com/usn/usn-494-1http://www.vupen.com/english/advisories/2007/2471https://exchange.xforce.ibmcloud.com/vulnerabilities/35308https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10842
2007-07-10
Published