CVE-2010-4543
published 2011-01-07CVE-2010-4543: Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a…
PriorityP352high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
16.27%
96.6th percentile
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.6.11-2 (bookworm) | gimp 2.6.11-2 (bookworm) |
| debian | gimp | < gimp 2.6.11-3 (bookworm) | gimp 2.6.11-3 (bookworm) |
| gimp | gimp | — | — |
| gimp | gimp | >= 0 < 2.6.11-3 | 2.6.11-3 |
| gimp | gimp | >= 0 < 2.6.11-2 | 2.6.11-2 |
| gimp | gimp | >= 0 < 2.6.11-3 | 2.6.11-3 |
| gimp | gimp | >= 0 < 2.6.11-2 | 2.6.11-2 |
| gimp | gimp | >= 0 < 2.6.11-3 | 2.6.11-3 |
| gimp | gimp | >= 0 < 2.6.11-2 | 2.6.11-2 |
| gimp | gimp | >= 0 < 2.6.11-3 | 2.6.11-3 |
| gimp | gimp | >= 0 < 2.6.11-2 | 2.6.11-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
vendor_redhat·2011-05-23·CVSS 7.5
CVE-2011-1782 [HIGH] Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
Package: gimp (Red Hat Enterprise Linux 4) - Not affected
Package: gimp (Red Hat Enterprise Linux 5) - Not affected
Package: gimp (Red Hat Enterprise Linux 6) - Affected
Ubuntu
GIMP vulnerabilities
vendor_ubuntu·2011-04-13·CVSS 6.8
CVE-2010-4541 [MEDIUM] GIMP vulnerabilities
Title: GIMP vulnerabilities
Summary: GIMP could be made to run programs as your login if it opened a
specially crafted file.
It was discovered that GIMP incorrectly handled malformed data in certain
plugin configuration files. If a user were tricked into opening a specially
crafted plugin configuration file, an attacker could cause GIMP to crash,
or possibly execute arbitrary code with the user's privileges. The default
compiler options for affected releases should reduce the vulnerability to a
denial of service. (CVE-2010-4540, CVE-2010-4541, CVE-2010-4542)
It was discovered that GIMP incorrectly handled malformed PSP image files.
If a user were tricked into opening a specially crafted PSP image file, an
attacker could cause GIMP to crash, or possibly execute arbitrary code with
the us
Debian
CVE-2011-1782: gimp - Heap-based buffer overflow in the read_channel_data function in file-psp.c in th...
vendor_debian·2011·CVSS 7.5
CVE-2011-1782 [HIGH] CVE-2011-1782: gimp - Heap-based buffer overflow in the read_channel_data function in file-psp.c in th...
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
Scope: local
bookworm: resolved (fixed in 2.6.11-3)
bullseye: resolved (fixed in 2.6.11-3)
forky: resolved (fixed in 2.6.11-3)
sid: resolved (fixed in 2.6.11-3)
trixie: resolved (fixed in 2.6.11-3)
Red Hat
Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in
vendor_redhat·2010-12-31·CVSS 7.5
CVE-2010-4543 [HIGH] CWE-122 Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in
Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information.
Debian
CVE-2010-4543: gimp - Heap-based buffer overflow in the read_channel_data function in file-psp.c in th...
vendor_debian·2010·CVSS 7.5
CVE-2010-4543 [HIGH] CVE-2010-4543: gimp - Heap-based buffer overflow in the read_channel_data function in file-psp.c in th...
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 2.6.11-2)
bullseye: resolved (fixed in 2.6.11-2)
forky: resolved (fixed in 2.6.11-2)
sid: resolved (fixed in 2.6.11-2)
trixie: resolved (fixed in 2.6.11-2)
GHSA
GHSA-6cq7-qh8g-jvqf: Heap-based buffer overflow in the read_channel_data function in file-psp
ghsa_unreviewed·2022-05-13
CVE-2010-4543 [HIGH] CWE-787 GHSA-6cq7-qh8g-jvqf: Heap-based buffer overflow in the read_channel_data function in file-psp
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information.
GHSA
GHSA-q2hq-v4x4-w3r5: Heap-based buffer overflow in the read_channel_data function in file-psp
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2011-1782 [HIGH] CWE-787 GHSA-q2hq-v4x4-w3r5: Heap-based buffer overflow in the read_channel_data function in file-psp
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
OSV
CVE-2011-1782: Heap-based buffer overflow in the read_channel_data function in file-psp
osv·2011-07-27·CVSS 7.5
CVE-2011-1782 [HIGH] CVE-2011-1782: Heap-based buffer overflow in the read_channel_data function in file-psp
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
OSV
CVE-2010-4543: Heap-based buffer overflow in the read_channel_data function in file-psp
osv·2011-01-07·CVSS 7.5
CVE-2010-4543 [HIGH] CVE-2010-4543: Heap-based buffer overflow in the read_channel_data function in file-psp
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information.
No detection rules found.
Bugzilla
CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
bugzilla·2011-05-23·CVSS 6.8
CVE-2010-4540 [MEDIUM] CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=666793
Bugzilla
CVE-2011-1782 Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
bugzilla·2011-05-13·CVSS 7.5
CVE-2011-1782 [HIGH] CVE-2011-1782 Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
CVE-2011-1782 Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
Originally Common Vulnerabilities and Exposures assigned an identifier
of CVE-2010-4543 to the following vulnerability:
Heap-based buffer overflow in the read_channel_data function in file-psp.c
in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to
cause a denial of service (application crash) or possibly execute arbitrary
code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long
run count at the end of the image. NOTE: some of these details are obtained
from third party information.
Upstream bug report:
[1] https://bugzilla.gnome.org/show_bug.cgi?id=639203
Original patch proposal from Vincent Untz:
[2] https://bugzilla.gnome.org/show_bug.cgi?id=639203#c12
And
Bugzilla
CVE-2010-4543 Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in
bugzilla·2011-05-10·CVSS 7.5
CVE-2010-4543 [HIGH] CVE-2010-4543 Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in
CVE-2010-4543 Gimp: Heap-based buffer overflow in Paint Shop Pro (PSP) plug-in
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4543 to
the following vulnerability:
Heap-based buffer overflow in the read_channel_data function in file-psp.c
in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers
to cause a denial of service (application crash) or possibly execute arbitrary
code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long
run count at the end of the image. NOTE: some of these details are obtained
from third party information.
References:
[1] http://openwall.com/lists/oss-security/2011/01/03/2
[2] http://openwall.com/lists/oss-security/2011/01/04/7
[3] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497
[4] https://bugzil
Bugzilla
CVE-2010-4540 Gimp: Stack-based buffer overflow in Lighting plug-in
bugzilla·2011-01-03·CVSS 6.8
CVE-2010-4540 [MEDIUM] CVE-2010-4540 Gimp: Stack-based buffer overflow in Lighting plug-in
CVE-2010-4540 Gimp: Stack-based buffer overflow in Lighting plug-in
Several stack-based buffer overflows were found in the way gimp
processes plug-in configuration files. An attacker could create a
a specially-crafted plug-in configuration file and trick the local,
unsuspecting user into opening it, which could lead to gimp to crash
the plugin or, potentially , arbitrary code execution with
the privileges of the user running the executable.
Reference:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497
Public PoC:
http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;filename=gimp-overflows-poc-in-cobol.cob;att=1;bug=608497
Flaw severity note:
On systems with compile time buffer checks (FORTIFY_SOURCE)
feature enabled, the impact of this flaw is mitigated to
be only crash.
Discussio
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2011/01/03/2http://openwall.com/lists/oss-security/2011/01/04/7http://osvdb.org/70284http://secunia.com/advisories/42771http://secunia.com/advisories/44750http://secunia.com/advisories/48236http://secunia.com/advisories/50737http://security.gentoo.org/glsa/glsa-201209-23.xmlhttp://www.debian.org/security/2012/dsa-2426http://www.mandriva.com/security/advisories?name=MDVSA-2011:103http://www.redhat.com/support/errata/RHSA-2011-0837.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0838.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0839.htmlhttp://www.vupen.com/english/advisories/2011/0016https://bugzilla.redhat.com/show_bug.cgi?id=666793http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2011/01/03/2http://openwall.com/lists/oss-security/2011/01/04/7http://osvdb.org/70284http://secunia.com/advisories/42771http://secunia.com/advisories/44750http://secunia.com/advisories/48236http://secunia.com/advisories/50737http://security.gentoo.org/glsa/glsa-201209-23.xmlhttp://www.debian.org/security/2012/dsa-2426http://www.mandriva.com/security/advisories?name=MDVSA-2011:103http://www.redhat.com/support/errata/RHSA-2011-0837.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0838.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0839.htmlhttp://www.vupen.com/english/advisories/2011/0016https://bugzilla.redhat.com/show_bug.cgi?id=666793
2011-01-07
Published