CVE-2012-3236
published 2012-07-12CVE-2012-3236: fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EXPLOIT
EPSS
10.75%
95.4th percentile
fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 2.8.2-1 (bookworm) | gimp 2.8.2-1 (bookworm) |
| gimp | gimp | < 2.9.2 | 2.9.2 |
| gimp | gimp | >= 0 < 2.8.2-1 | 2.8.2-1 |
| gimp | gimp | >= 0 < 2.8.2-1 | 2.8.2-1 |
| gimp | gimp | >= 0 < 2.8.2-1 | 2.8.2-1 |
| gimp | gimp | >= 0 < 2.8.2-1 | 2.8.2-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4g36-rrq2-qqqf: fits-io
ghsa_unreviewed·2022-05-13
CVE-2012-3236 [MEDIUM] CWE-476 GHSA-4g36-rrq2-qqqf: fits-io
fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
OSV
CVE-2012-3236: fits-io
osv·2012-07-12·CVSS 4.3
CVE-2012-3236 [MEDIUM] CVE-2012-3236: fits-io
fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
Ubuntu
GIMP vulnerabilities
vendor_ubuntu·2012-09-10·CVSS 4.3
CVE-2012-3236 [MEDIUM] GIMP vulnerabilities
Title: GIMP vulnerabilities
Summary: GIMP could be made to crash or run programs as your login if it opened a
specially crafted file.
Joseph Sheridan discovered that GIMP incorrectly handled certain malformed
headers in FIT files. If a user were tricked into opening a specially
crafted FIT image file, an attacker could cause GIMP to crash.
(CVE-2012-3236)
Murray McAllister discovered that GIMP incorrectly handled malformed KiSS
palette files. If a user were tricked into opening a specially crafted KiSS
palette file, an attacker could cause GIMP to crash, or possibly execute
arbitrary code with the user's privileges. (CVE-2012-3403)
Matthias Weckbecker discovered that GIMP incorrectly handled malformed GIF
image files. If a user were tricked into opening a specially crafted GIF
image fi
Red Hat
gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header
vendor_redhat·2012-06-29·CVSS 4.3
CVE-2012-3236 [MEDIUM] CWE-476 gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header
gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header
fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
Statement: We do not consider a user-assisted crash of a client application such as Gimp to be a security issue.
Package: gimp (Red Hat Enterprise Linux 5) - Not affected
Package: gimp (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-3236: gimp - fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of serv...
vendor_debian·2012·CVSS 4.3
CVE-2012-3236 [MEDIUM] CVE-2012-3236: gimp - fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of serv...
fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
Scope: local
bookworm: resolved (fixed in 2.8.2-1)
bullseye: resolved (fixed in 2.8.2-1)
forky: resolved (fixed in 2.8.2-1)
sid: resolved (fixed in 2.8.2-1)
trixie: resolved (fixed in 2.8.2-1)
No detection rules found.
Bugzilla
CVE-2012-3236 gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header [fedora-all]
bugzilla·2012-06-29·CVSS 4.3
CVE-2012-3236 [MEDIUM] CVE-2012-3236 gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header [fedora-all]
CVE-2012-3236 gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraprojec
Bugzilla
CVE-2012-3236 gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header
bugzilla·2012-06-22·CVSS 4.3
CVE-2012-3236 [MEDIUM] CVE-2012-3236 gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header
CVE-2012-3236 gimp: NULL pointer deref crash when reading FIT file with crafted XTENSION header
A denial of service flaw was found in the way GIMP, GNU Image Manipulation Program, processed certain FIT format files. A remote attacker could provide a FIT format file with specially-crafted value of the 'XTENSION' header that, when opened would cause the gimp executable to crash.
References:
[1] http://www.reactionpenetrationtesting.co.uk/advisories/FIT-handling-DoS.html
[2] http://www.reactionpenetrationtesting.co.uk/advisories/vuln.fit
Discussion:
Acknowledgements:
Red Hat would like to thank Joseph Sheridan for reporting this issue.
---
Upstream bug and commit:
https://bugzilla.gnome.org/show_bug.cgi?id=676804
http://git.gnome.org/browse/gimp/commit/plug-ins/file-fits/fits-io.c?id=a
http://archives.neohapsis.com/archives/bugtraq/2012-06/0192.htmlhttp://git.gnome.org/browse/gimp/commit/plug-ins/file-fits/fits-io.c?id=ace45631595e8781a1420842582d67160097163chttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00000.htmlhttp://www.exploit-db.com/exploits/19482http://www.mandriva.com/security/advisories?name=MDVSA-2013:082http://www.reactionpenetrationtesting.co.uk/FIT-file-handling-dos.htmlhttp://www.securityfocus.com/bid/54246http://www.ubuntu.com/usn/USN-1559-1https://bugzilla.gnome.org/show_bug.cgi?id=676804https://exchange.xforce.ibmcloud.com/vulnerabilities/76658http://archives.neohapsis.com/archives/bugtraq/2012-06/0192.htmlhttp://git.gnome.org/browse/gimp/commit/plug-ins/file-fits/fits-io.c?id=ace45631595e8781a1420842582d67160097163chttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00000.htmlhttp://www.exploit-db.com/exploits/19482http://www.mandriva.com/security/advisories?name=MDVSA-2013:082http://www.reactionpenetrationtesting.co.uk/FIT-file-handling-dos.htmlhttp://www.securityfocus.com/bid/54246http://www.ubuntu.com/usn/USN-1559-1https://bugzilla.gnome.org/show_bug.cgi?id=676804https://exchange.xforce.ibmcloud.com/vulnerabilities/76658
2012-07-12
Published