CVE-2011-1782
published 2011-07-27CVE-2011-1782: Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.43%
87.7th percentile
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.6.11-3 (bookworm) | gimp 2.6.11-3 (bookworm) |
| gimp | gimp | — | — |
| gimp | gimp | >= 0 < 2.6.11-3 | 2.6.11-3 |
| gimp | gimp | >= 0 < 2.6.11-3 | 2.6.11-3 |
| gimp | gimp | >= 0 < 2.6.11-3 | 2.6.11-3 |
| gimp | gimp | >= 0 < 2.6.11-3 | 2.6.11-3 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GIMP vulnerability
vendor_ubuntu·2011-06-13
CVE-2011-1782 GIMP vulnerability
Title: GIMP vulnerability
Summary: GIMP could be made to run programs as your login if it opened a
specially crafted file.
Nils Philippsen discovered that GIMP incorrectly handled malformed PSP
image files. If a user were tricked into opening a specially crafted PSP
image file, an attacker could cause GIMP to crash, or possibly execute
arbitrary code with the user's privileges.
Instructions: After a standard system update you need to restart GIMP to make all the
necessary changes.
Red Hat
Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
vendor_redhat·2011-05-23·CVSS 7.5
CVE-2011-1782 [HIGH] Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
Package: gimp (Red Hat Enterprise Linux 4) - Not affected
Package: gimp (Red Hat Enterprise Linux 5) - Not affected
Package: gimp (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2011-1782: gimp - Heap-based buffer overflow in the read_channel_data function in file-psp.c in th...
vendor_debian·2011·CVSS 7.5
CVE-2011-1782 [HIGH] CVE-2011-1782: gimp - Heap-based buffer overflow in the read_channel_data function in file-psp.c in th...
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
Scope: local
bookworm: resolved (fixed in 2.6.11-3)
bullseye: resolved (fixed in 2.6.11-3)
forky: resolved (fixed in 2.6.11-3)
sid: resolved (fixed in 2.6.11-3)
trixie: resolved (fixed in 2.6.11-3)
GHSA
GHSA-q2hq-v4x4-w3r5: Heap-based buffer overflow in the read_channel_data function in file-psp
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2011-1782 [HIGH] CWE-787 GHSA-q2hq-v4x4-w3r5: Heap-based buffer overflow in the read_channel_data function in file-psp
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
OSV
CVE-2011-1782: Heap-based buffer overflow in the read_channel_data function in file-psp
osv·2011-07-27·CVSS 7.5
CVE-2011-1782 [HIGH] CVE-2011-1782: Heap-based buffer overflow in the read_channel_data function in file-psp
Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
bugzilla·2011-05-23·CVSS 6.8
CVE-2010-4540 [MEDIUM] CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
CVE-2010-4540 CVE-2010-4541 CVE-2010-4542 CVE-2010-4543 CVE-2011-1782 CVE-2010-4543 gimp various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=666793
Bugzilla
CVE-2011-1782 Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
bugzilla·2011-05-13·CVSS 7.5
CVE-2011-1782 [HIGH] CVE-2011-1782 Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
CVE-2011-1782 Gimp: Incomplete fix for CVE-2010-4543 PSP plug-in heap overflow issue
Originally Common Vulnerabilities and Exposures assigned an identifier
of CVE-2010-4543 to the following vulnerability:
Heap-based buffer overflow in the read_channel_data function in file-psp.c
in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to
cause a denial of service (application crash) or possibly execute arbitrary
code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long
run count at the end of the image. NOTE: some of these details are obtained
from third party information.
Upstream bug report:
[1] https://bugzilla.gnome.org/show_bug.cgi?id=639203
Original patch proposal from Vincent Untz:
[2] https://bugzilla.gnome.org/show_bug.cgi?id=639203#c12
And
http://secunia.com/advisories/48236http://www.debian.org/security/2012/dsa-2426http://www.mandriva.com/security/advisories?name=MDVSA-2011:103https://bugzilla.redhat.com/show_bug.cgi?id=704512http://secunia.com/advisories/48236http://www.debian.org/security/2012/dsa-2426http://www.mandriva.com/security/advisories?name=MDVSA-2011:103https://bugzilla.redhat.com/show_bug.cgi?id=704512
2011-07-27
Published