CVE-2017-17785Out-of-bounds Write in Gimp

Severity
7.8HIGHNVD
EPSS
0.4%
top 41.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateFeb 23

Description

In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debiangimp/gimp< 2.8.20-1.1+3
Ubuntugimp/gimp< 2.8.10-0ubuntu1.2+5
NVDgimp/gimp2.8.22

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04

🔴Vulnerability Details

5
OSV
gimp vulnerabilities2026-02-23
GHSA
GHSA-p42j-f8w2-5pxc: In GIMP 22022-05-13
OSV
gimp vulnerabilities2018-01-22
OSV
CVE-2017-17785: In GIMP 22017-12-20
CVEList
CVE-2017-17785: In GIMP 22017-12-20

📋Vendor Advisories

4
Ubuntu
GIMP vulnerabilities2026-02-23
Ubuntu
GIMP vulnerabilities2018-01-22
Red Hat
gimp: Heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c2017-12-19
Debian
CVE-2017-17785: gimp - In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun funct...2017

💬Community

2
Bugzilla
CVE-2017-17784 CVE-2017-17785 CVE-2017-17786 CVE-2017-17787 CVE-2017-17788 CVE-2017-17789 gimp: various flaws [fedora-all]2017-12-26
Bugzilla
CVE-2017-17785 gimp: Heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c2017-12-26