CVE-2017-17788Out-of-bounds Read in Gimp

CWE-125Out-of-bounds Read10 documents8 sources
Severity
5.5MEDIUMNVD
OSV7.8
EPSS
0.5%
top 33.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateMay 13

Description

In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Debiangimp/gimp< 2.8.20-1.1+3
Ubuntugimp/gimp< 2.8.10-0ubuntu1.2
NVDgimp/gimp2.8.22

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04

🔴Vulnerability Details

4
GHSA
GHSA-wqmm-5cp8-rhmw: In GIMP 22022-05-13
OSV
gimp vulnerabilities2018-01-22
OSV
CVE-2017-17788: In GIMP 22017-12-20
CVEList
CVE-2017-17788: In GIMP 22017-12-20

📋Vendor Advisories

3
Ubuntu
GIMP vulnerabilities2018-01-22
Red Hat
gimp: Stack-based buffer over-read in xcf_load_stream function in app/xcf/xcf.c2017-12-19
Debian
CVE-2017-17788: gimp - In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in ap...2017

💬Community

2
Bugzilla
CVE-2017-17784 CVE-2017-17785 CVE-2017-17786 CVE-2017-17787 CVE-2017-17788 CVE-2017-17789 gimp: various flaws [fedora-all]2017-12-26
Bugzilla
CVE-2017-17788 gimp: Stack-based buffer over-read in xcf_load_stream function in app/xcf/xcf.c2017-12-26