CVE-2010-4542
published 2011-01-07CVE-2010-4542: Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.57%
92.0th percentile
Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Foreground field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself. NOTE: some of these details are obtained from third party information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.6.11-2 (bookworm) | gimp 2.6.11-2 (bookworm) |
| gimp | gimp | — | — |
| gimp | gimp | >= 0 < 2.6.11-2 | 2.6.11-2 |
| gimp | gimp | >= 0 < 2.6.11-2 | 2.6.11-2 |
| gimp | gimp | >= 0 < 2.6.11-2 | 2.6.11-2 |
| gimp | gimp | >= 0 < 2.6.11-2 | 2.6.11-2 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r7vf-8935-3h3p: Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style
ghsa_unreviewed·2022-05-13
CVE-2010-4542 [MEDIUM] CWE-787 GHSA-r7vf-8935-3h3p: Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style
Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Foreground field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself. NOTE: some of these details are obtained from third party information.
OSV
CVE-2010-4542: Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style
osv·2011-01-07·CVSS 6.8
CVE-2010-4542 [MEDIUM] CVE-2010-4542: Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style
Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Foreground field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself. NOTE: some of these details are obtained from third party information.
Ubuntu
GIMP vulnerabilities
vendor_ubuntu·2011-04-13·CVSS 6.8
CVE-2010-4541 [MEDIUM] GIMP vulnerabilities
Title: GIMP vulnerabilities
Summary: GIMP could be made to run programs as your login if it opened a
specially crafted file.
It was discovered that GIMP incorrectly handled malformed data in certain
plugin configuration files. If a user were tricked into opening a specially
crafted plugin configuration file, an attacker could cause GIMP to crash,
or possibly execute arbitrary code with the user's privileges. The default
compiler options for affected releases should reduce the vulnerability to a
denial of service. (CVE-2010-4540, CVE-2010-4541, CVE-2010-4542)
It was discovered that GIMP incorrectly handled malformed PSP image files.
If a user were tricked into opening a specially crafted PSP image file, an
attacker could cause GIMP to crash, or possibly execute arbitrary code with
the us
Red Hat
Gimp: Stack-based buffer overflow in Gfig plug-in
vendor_redhat·2010-12-31·CVSS 6.8
CVE-2010-4542 [MEDIUM] CWE-121 Gimp: Stack-based buffer overflow in Gfig plug-in
Gimp: Stack-based buffer overflow in Gfig plug-in
Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Foreground field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself. NOTE: some of these details are obtained from third party information.
Package: gimp (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2010-4542: gimp - Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug...
vendor_debian·2010·CVSS 6.8
CVE-2010-4542 [MEDIUM] CVE-2010-4542: gimp - Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug...
Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Foreground field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 2.6.11-2)
bullseye: resolved (fixed in 2.6.11-2)
forky: resolved (fixed in 2.6.11-2)
sid: resolved (fixed in 2.6.11-2)
trixie: resolved (fixed in 2.6.11-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
bugzilla·2011-05-23·CVSS 6.8
CVE-2010-4540 [MEDIUM] CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=666793
Bugzilla
CVE-2010-4542 Gimp: Stack-based buffer overflow in Gfig plug-in
bugzilla·2011-05-10·CVSS 6.8
CVE-2010-4542 [MEDIUM] CVE-2010-4542 Gimp: Stack-based buffer overflow in Gfig plug-in
CVE-2010-4542 Gimp: Stack-based buffer overflow in Gfig plug-in
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4542 to
the following vulnerability:
Stack-based buffer overflow in the gfig_read_parameter_gimp_rgb function in
plug-ins/gfig/gfig-style.c in the GFIG plugin in GIMP 2.6.11 allows
user-assisted remote attackers to cause a denial of service (application
crash) or possibly execute arbitrary code via a long Foreground field in
a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP
plugin configuration file from an untrusted source that is separate from
the distribution of the plugin itself. NOTE: some of these details are
obtained from third party information.
References:
[1] http://openwall.com/lists/oss-security/2011/01/03/2
[2] http://open
Bugzilla
CVE-2010-4540 Gimp: Stack-based buffer overflow in Lighting plug-in
bugzilla·2011-01-03·CVSS 6.8
CVE-2010-4540 [MEDIUM] CVE-2010-4540 Gimp: Stack-based buffer overflow in Lighting plug-in
CVE-2010-4540 Gimp: Stack-based buffer overflow in Lighting plug-in
Several stack-based buffer overflows were found in the way gimp
processes plug-in configuration files. An attacker could create a
a specially-crafted plug-in configuration file and trick the local,
unsuspecting user into opening it, which could lead to gimp to crash
the plugin or, potentially , arbitrary code execution with
the privileges of the user running the executable.
Reference:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497
Public PoC:
http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;filename=gimp-overflows-poc-in-cobol.cob;att=1;bug=608497
Flaw severity note:
On systems with compile time buffer checks (FORTIFY_SOURCE)
feature enabled, the impact of this flaw is mitigated to
be only crash.
Discussio
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2011/01/03/2http://openwall.com/lists/oss-security/2011/01/04/7http://osvdb.org/70283http://secunia.com/advisories/42771http://secunia.com/advisories/44750http://secunia.com/advisories/48236http://secunia.com/advisories/50737http://security.gentoo.org/glsa/glsa-201209-23.xmlhttp://www.debian.org/security/2012/dsa-2426http://www.mandriva.com/security/advisories?name=MDVSA-2011:103http://www.redhat.com/support/errata/RHSA-2011-0838.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0839.htmlhttp://www.vupen.com/english/advisories/2011/0016https://bugzilla.redhat.com/show_bug.cgi?id=666793http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2011/01/03/2http://openwall.com/lists/oss-security/2011/01/04/7http://osvdb.org/70283http://secunia.com/advisories/42771http://secunia.com/advisories/44750http://secunia.com/advisories/48236http://secunia.com/advisories/50737http://security.gentoo.org/glsa/glsa-201209-23.xmlhttp://www.debian.org/security/2012/dsa-2426http://www.mandriva.com/security/advisories?name=MDVSA-2011:103http://www.redhat.com/support/errata/RHSA-2011-0838.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0839.htmlhttp://www.vupen.com/english/advisories/2011/0016https://bugzilla.redhat.com/show_bug.cgi?id=666793
2011-01-07
Published