CVE-2009-0581Missing Release of Memory after Effective Lifetime in Gimp

Severity
4.3MEDIUMNVD
EPSS
1.9%
top 16.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMay 2

Description

Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

NVDgimp/gimp< 2.9.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2m87-9x7m-6v4q: Memory leak in LittleCMS (aka lcms or liblcms) before 12022-05-02
CVEList
CVE-2009-0581: Memory leak in LittleCMS (aka lcms or liblcms) before 12009-03-23

📋Vendor Advisories

2
Ubuntu
LittleCMS vulnerabilities2009-03-23
Red Hat
LittleCms memory leak2009-03-19

💬Community

1
Bugzilla
CVE-2009-0581 LittleCms memory leak2009-02-26
CVE-2009-0581 — Gimp vulnerability | cvebase