CVE-2007-3741
published 2007-08-27CVE-2007-3741: The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.62%
83.9th percentile
The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.2.17-1 (bookworm) | gimp 2.2.17-1 (bookworm) |
| gimp | gimp | >= 0 < 2.2.17-1 | 2.2.17-1 |
| gimp | gimp | >= 0 < 2.2.17-1 | 2.2.17-1 |
| gimp | gimp | >= 0 < 2.2.17-1 | 2.2.17-1 |
| gimp | gimp | >= 0 < 2.2.17-1 | 2.2.17-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Gimp image loader multiple input validation flaws
vendor_redhat·2007-07-09·CVSS 4.3
CVE-2007-3741 [MEDIUM] CWE-20 Gimp image loader multiple input validation flaws
Gimp image loader multiple input validation flaws
The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.
Debian
CVE-2007-3741: gimp - The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user...
vendor_debian·2007·CVSS 4.3
CVE-2007-3741 [MEDIUM] CVE-2007-3741: gimp - The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user...
The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.
Scope: local
bookworm: resolved (fixed in 2.2.17-1)
bullseye: resolved (fixed in 2.2.17-1)
forky: resolved (fixed in 2.2.17-1)
sid: resolved (fixed in 2.2.17-1)
trixie: resolved (fixed in 2.2.17-1)
GHSA
GHSA-7624-6867-rjhv: The (1) psp (aka
ghsa_unreviewed·2022-05-01
CVE-2007-3741 [MEDIUM] GHSA-7624-6867-rjhv: The (1) psp (aka
The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.
OSV
CVE-2007-3741: The (1) psp (aka
osv·2007-08-27·CVSS 4.3
CVE-2007-3741 [MEDIUM] CVE-2007-3741: The (1) psp (aka
The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3741 Gimp image loader multiple input validation flaws
bugzilla·2007-07-12·CVSS 4.3
CVE-2007-3741 [MEDIUM] CVE-2007-3741 Gimp image loader multiple input validation flaws
CVE-2007-3741 Gimp image loader multiple input validation flaws
The release of Gimp 2.2.16 fixed this item:
- improved input value validation in several file plug-ins (bug #453973)
This bug:
http://bugzilla.gnome.org/show_bug.cgi?id=453973
fixes several input validation flaws in the way the Gimp loads various
Discussion:
the psd fixes cause a regression with images that contain zero
width/height layers
---
waiting for 2.2.17 which should be ready soon
---
built pkgs for RHEL2.1 - RHEL5 with fixes for (as of yet) known security issues
---
This was addressed via:
Red Hat Enterprise Linux version 2.1 (RHSA-2007:0513)
Red Hat Enterprise Linux version 3 (RHSA-2007:0513)
Red Hat Enterprise Linux version 4 (RHSA-2007:0513)
Red Hat Enterprise Linux version 5 (RHSA-2007:0513)
Bugzilla
CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [FC6]
bugzilla·2007-07-10·CVSS 6.8
CVE-2006-4519 [MEDIUM] CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [FC6]
CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
supposed to be fixed in gimp-2.2.16-1.fc6 which is in updates-testing
---
gimp-2.2.16-2.fc6
---
gimp-2.2.17-1.fc6
---
Nils, is this fixed in FEDORA-2007-627 (gimp-2.2.17-1.fc6)?
If yes, is there any reason for not closing this bug?
---
No, there isn't.
Bugzilla
CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [Fdevel]
bugzilla·2007-07-10·CVSS 6.8
CVE-2006-4519 [MEDIUM] CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [Fdevel]
CVE-2006-4519, CVE-2007-3741 GIMP multiple image loader integer overflows [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
supposed to be fixed in gimp-2.2.16-1.fc8 which is built already, should hit
Rawhide with the next compose/push
---
regressions popped up, fixed in gimp-2.2.17-1.fc8, should hit Rawhide with the
next compose/push
http://osvdb.org/42128http://osvdb.org/42129http://osvdb.org/42130http://osvdb.org/42131http://secunia.com/advisories/26575http://secunia.com/advisories/26939http://www.mandriva.com/security/advisories?name=MDKSA-2007:170http://www.redhat.com/support/errata/RHSA-2007-0513.htmlhttp://www.securityfocus.com/bid/25424https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10099http://osvdb.org/42128http://osvdb.org/42129http://osvdb.org/42130http://osvdb.org/42131http://secunia.com/advisories/26575http://secunia.com/advisories/26939http://www.mandriva.com/security/advisories?name=MDKSA-2007:170http://www.redhat.com/support/errata/RHSA-2007-0513.htmlhttp://www.securityfocus.com/bid/25424https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10099
2007-08-27
Published