CVE-2007-3126
published 2007-06-08CVE-2007-3126: Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a…
PriorityP414medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.85%
85.2th percentile
Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.8.22-1 (bookworm) | gimp 2.8.22-1 (bookworm) |
| gimp | gimp | < 2.8.22 | 2.8.22 |
| gimp | gimp | >= 0 < 2.8.22-1 | 2.8.22-1 |
| gimp | gimp | >= 0 < 2.8.22-1 | 2.8.22-1 |
| gimp | gimp | >= 0 < 2.8.22-1 | 2.8.22-1 |
| gimp | gimp | >= 0 < 2.8.22-1 | 2.8.22-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Gimp: context-dependent attackers to cause a denial of service
vendor_redhat·2022-02-07·CVSS 5.5
CVE-2007-3126 [MEDIUM] CWE-400 Gimp: context-dependent attackers to cause a denial of service
Gimp: context-dependent attackers to cause a denial of service
Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
Statement: Red Hat does not consider a user-assisted crash of a user application such as GIMP to be a security issue.
Package: gimp (Red Hat Enterprise Linux 6) - Out of support scope
Package: gimp (Red Hat Enterprise Linux 7) - Not affected
Package: gimp:2.8/gimp (Red Hat Enterprise Linux 8) - Not affected
Package: gimp:flatpak/gimp (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2007-3126: gimp - Gimp before 2.8.22 allows context-dependent attackers to cause a denial of servi...
vendor_debian·2007·CVSS 5.5
CVE-2007-3126 [MEDIUM] CVE-2007-3126: gimp - Gimp before 2.8.22 allows context-dependent attackers to cause a denial of servi...
Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
Scope: local
bookworm: resolved (fixed in 2.8.22-1)
bullseye: resolved (fixed in 2.8.22-1)
forky: resolved (fixed in 2.8.22-1)
sid: resolved (fixed in 2.8.22-1)
trixie: resolved (fixed in 2.8.22-1)
GHSA
GHSA-4vhr-6jhx-vf2q: Gimp before 2
ghsa_unreviewed·2022-05-01·CVSS 5.5
CVE-2007-3126 [MEDIUM] GHSA-4vhr-6jhx-vf2q: Gimp before 2
Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
OSV
CVE-2007-3126: Gimp before 2
osv·2007-06-08·CVSS 5.5
CVE-2007-3126 [MEDIUM] CVE-2007-3126: Gimp before 2
Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/43453http://www.securityfocus.com/archive/1/470751/100/0/threadedhttps://bugzilla.gnome.org/show_bug.cgi?id=778604https://exchange.xforce.ibmcloud.com/vulnerabilities/34789https://git.gnome.org/browse/gimp/commit/?id=323ecb73f7bf36788fb7066eb2d6678830cd5de7https://www.gimp.org/news/2017/05/11/gimp-2-8-22-released/http://osvdb.org/43453http://www.securityfocus.com/archive/1/470751/100/0/threadedhttps://bugzilla.gnome.org/show_bug.cgi?id=778604https://exchange.xforce.ibmcloud.com/vulnerabilities/34789https://git.gnome.org/browse/gimp/commit/?id=323ecb73f7bf36788fb7066eb2d6678830cd5de7https://www.gimp.org/news/2017/05/11/gimp-2-8-22-released/
2007-06-08
Published