cbcvebase.
CVE-2006-4519
published 2007-07-10

CVE-2006-4519: Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiangimp< gimp 2.2.16-1 (bookworm)gimp 2.2.16-1 (bookworm)
gimpgimp< 2.2.162.2.16
gimpgimp>= 0 < 2.2.16-12.2.16-1
gimpgimp>= 0 < 2.2.16-12.2.16-1
gimpgimp>= 0 < 2.2.16-12.2.16-1
gimpgimp>= 0 < 2.2.16-12.2.16-1

CVSS provenance

nvd6.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM