CVE-2009-3909
published 2009-11-19CVE-2009-3909: Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.69%
94.5th percentile
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.6.7-1.1 (bookworm) | gimp 2.6.7-1.1 (bookworm) |
| debian | gimp | < gimp 2.4.0~rc1-1 (bookworm) | gimp 2.4.0~rc1-1 (bookworm) |
| gimp | gimp | <= 2.2.13 | — |
| gimp | gimp | — | — |
| gimp | gimp | >= 0 < 2.6.7-1.1 | 2.6.7-1.1 |
| gimp | gimp | >= 0 < 2.4.0~rc1-1 | 2.4.0~rc1-1 |
| gimp | gimp | >= 0 < 2.6.7-1.1 | 2.6.7-1.1 |
| gimp | gimp | >= 0 < 2.4.0~rc1-1 | 2.4.0~rc1-1 |
| gimp | gimp | >= 0 < 2.6.7-1.1 | 2.6.7-1.1 |
| gimp | gimp | >= 0 < 2.4.0~rc1-1 | 2.4.0~rc1-1 |
| gimp | gimp | >= 0 < 2.6.7-1.1 | 2.6.7-1.1 |
| gimp | gimp | >= 0 < 2.4.0~rc1-1 | 2.4.0~rc1-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hphq-v97j-xqw4: Integer overflow in plug-ins/common/psd
ghsa_unreviewed·2022-05-13·CVSS 9.3
CVE-2012-3402 [CRITICAL] CWE-190 GHSA-hphq-v97j-xqw4: Integer overflow in plug-ins/common/psd
Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in GIMP 2.2.13 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted channels header value in a PSD image file, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2009-3909.
GHSA
GHSA-7456-jpq8-24rh: Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load
ghsa_unreviewed·2022-05-02
CVE-2009-3909 [HIGH] CWE-190 GHSA-7456-jpq8-24rh: Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.
OSV
CVE-2012-3402: Integer overflow in plug-ins/common/psd
osv·2012-08-25·CVSS 9.3
CVE-2012-3402 [CRITICAL] CVE-2012-3402: Integer overflow in plug-ins/common/psd
Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in GIMP 2.2.13 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted channels header value in a PSD image file, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2009-3909.
OSV
CVE-2009-3909: Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load
osv·2009-11-19·CVSS 9.3
CVE-2009-3909 [CRITICAL] CVE-2009-3909: Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.
Red Hat
plug-in): Heap-buffer overflow by decoding certain PSD headers
vendor_redhat·2012-08-20·CVSS 9.3
CVE-2012-3402 [CRITICAL] CWE-122 plug-in): Heap-buffer overflow by decoding certain PSD headers
plug-in): Heap-buffer overflow by decoding certain PSD headers
Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in GIMP 2.2.13 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted channels header value in a PSD image file, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2009-3909.
Package: gimp (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-3402: gimp - Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in G...
vendor_debian·2012·CVSS 9.3
CVE-2012-3402 [CRITICAL] CVE-2012-3402: gimp - Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in G...
Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in GIMP 2.2.13 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted channels header value in a PSD image file, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2009-3909.
Scope: local
bookworm: resolved (fixed in 2.4.0~rc1-1)
bullseye: resolved (fixed in 2.4.0~rc1-1)
forky: resolved (fixed in 2.4.0~rc1-1)
sid: resolved (fixed in 2.4.0~rc1-1)
trixie: resolved (fixed in 2.4.0~rc1-1)
Ubuntu
GIMP vulnerabilities
vendor_ubuntu·2010-01-07·CVSS 9.3
CVE-2009-3909 [CRITICAL] GIMP vulnerabilities
Title: GIMP vulnerabilities
Summary: GIMP vulnerabilities
Stefan Cornelius discovered that GIMP did not correctly handle certain
malformed BMP files. If a user were tricked into opening a specially
crafted BMP file, an attacker could execute arbitrary code with the user's
privileges. (CVE-2009-1570)
Stefan Cornelius discovered that GIMP did not correctly handle certain
malformed PSD files. If a user were tricked into opening a specially
crafted PSD file, an attacker could execute arbitrary code with the user's
privileges. This issue only applied to Ubuntu 8.10, 9.04 and 9.10.
(CVE-2009-3909)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
Gimp: Integer overflow in the PSD image file plugin
vendor_redhat·2009-11-17·CVSS 9.3
CVE-2009-3909 [CRITICAL] CWE-190 Gimp: Integer overflow in the PSD image file plugin
Gimp: Integer overflow in the PSD image file plugin
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.
Statement: Vulnerable. This issue affects gimp packages in Red Hat Enterprise Linux 4 and 5. This issue does not affect gimp package in Red Hat Enterprise Linux 6.
Package: gimp (Red Hat Enterprise Linux 4) - Will not fix
Package: gimp (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2009-3909: gimp - Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load...
vendor_debian·2009·CVSS 9.3
CVE-2009-3909 [CRITICAL] CVE-2009-3909: gimp - Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load...
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.6.7-1.1)
bullseye: resolved (fixed in 2.6.7-1.1)
forky: resolved (fixed in 2.6.7-1.1)
sid: resolved (fixed in 2.6.7-1.1)
trixie: resolved (fixed in 2.6.7-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3402 gimp (PSD plug-in): Heap-buffer overflow by decoding certain PSD headers
bugzilla·2012-07-10·CVSS 6.8
CVE-2012-3402 [MEDIUM] CVE-2012-3402 gimp (PSD plug-in): Heap-buffer overflow by decoding certain PSD headers
CVE-2012-3402 gimp (PSD plug-in): Heap-buffer overflow by decoding certain PSD headers
A heap-based buffer overflow flaw was found in the way Adobe Photoshop(tm) PSD plug-in of Gimp, the GNU Image Manipulation Program, performed decoding of headers, when loading certain Adobe Photoshop image files. A remote attacker could provide a specially-crafted PSD image file that, when opened in Gimp would lead to PSD plug-in crash or, potentially, arbitrary code execution with the privileges of the user running gimp executable.
This issue was found by Jan Lieskovsky of the Red Hat Security Response Team
Discussion:
The CVE identifier of CVE-2012-3402 has been assigned to this issue.
---
Created attachment 603059
Patch to fix CVEs 2009-3909 and 2012-3402
---
This issue has been addressed in f
Bugzilla
CVE-2009-3909 Gimp: Integer overflow in the PSD image file plugin
bugzilla·2009-11-13·CVSS 9.3
CVE-2009-3909 [CRITICAL] CVE-2009-3909 Gimp: Integer overflow in the PSD image file plugin
CVE-2009-3909 Gimp: Integer overflow in the PSD image file plugin
Stefan Cornelius of Secunia Research reported an integer overflow,
leading to heap-based buffer overflow, present in Gimp's Adobe's
Photoshop (PSD) image file plugin. A remote attacker could
provide a specially-crafted PSD image file, which once opened
by a local, unsuspecting user would lead to denial of service
(GIMP PSD plugin crash).
Upstream patch:
http://git.gnome.org/cgit/gimp/commit/?h=gimp-2-6&id=88eccea84aa375197cc04a2a0e2e29debb56bfa5
The another PSD related commit might be needed too though:
http://git.gnome.org/cgit/gimp/commit/?h=gimp-2-6&id=687ec47914ec08d6e460918cb641c196d80140a3
Acknowledgements:
Red Hat would like to thank Stefan Cornelius of Secunia Research for reporting this flaw.
Discussion:
This
http://git.gnome.org/cgit/gimp/commit/?id=0e440cb6d4d6ee029667363d244aff61b154c33chttp://git.gnome.org/cgit/gimp/commit/?id=9cc8d78ff33b7a36852b74e64b427489cad44d0ehttp://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.htmlhttp://osvdb.org/60178http://rhn.redhat.com/errata/RHSA-2012-1181.htmlhttp://secunia.com/advisories/37348http://secunia.com/advisories/50737http://secunia.com/secunia_research/2009-43/http://security.gentoo.org/glsa/glsa-201209-23.xmlhttp://www.debian.org/security/2009/dsa-1941http://www.mandriva.com/security/advisories?name=MDVSA-2009:332http://www.securityfocus.com/archive/1/507928/100/0/threadedhttp://www.securityfocus.com/bid/37040http://www.vupen.com/english/advisories/2009/3270http://www.vupen.com/english/advisories/2010/1021https://bugzilla.gnome.org/show_bug.cgi?id=600741http://git.gnome.org/cgit/gimp/commit/?id=0e440cb6d4d6ee029667363d244aff61b154c33chttp://git.gnome.org/cgit/gimp/commit/?id=9cc8d78ff33b7a36852b74e64b427489cad44d0ehttp://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.htmlhttp://osvdb.org/60178http://rhn.redhat.com/errata/RHSA-2012-1181.htmlhttp://secunia.com/advisories/37348http://secunia.com/advisories/50737http://secunia.com/secunia_research/2009-43/http://security.gentoo.org/glsa/glsa-201209-23.xmlhttp://www.debian.org/security/2009/dsa-1941http://www.mandriva.com/security/advisories?name=MDVSA-2009:332http://www.securityfocus.com/archive/1/507928/100/0/threadedhttp://www.securityfocus.com/bid/37040http://www.vupen.com/english/advisories/2009/3270http://www.vupen.com/english/advisories/2010/1021https://bugzilla.gnome.org/show_bug.cgi?id=600741
2009-11-19
Published