CVE-2018-12713
published 2018-06-24CVE-2018-12713: GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the…
PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.95%
78.1th percentile
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gimp | < gimp 3.0.0~RC1-4 (forky) | gimp 3.0.0~RC1-4 (forky) |
| gimp | gimp | <= 2.10.2 | — |
| gimp | gimp | >= 0 < 3.0.0~RC1-4 | 3.0.0~RC1-4 |
| gimp | gimp | >= 0 < 3.0.0~RC1-4 | 3.0.0~RC1-4 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1LOW
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gimp: predictable temporary file name in test-xcf.c unit test
vendor_redhat·2018-06-21·CVSS 9.1
CVE-2018-12713 [CRITICAL] CWE-20 gimp: predictable temporary file name in test-xcf.c unit test
gimp: predictable temporary file name in test-xcf.c unit test
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.
Statement: This issue did affect the versions of gimp as shipped with Red Hat Enterprise Linux 7. However, as this is an issue in a unit test, it is not a problem if you are using the precompiled gimp package. This is only a problem if you recompile gimp using the src.rpm/SPEC file. Even then it's only a problem if you do not make use of isolating build tools like mock, but instead use rpmbuild directly.
Pac
Debian
CVE-2018-12713: gimp - GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, ...
vendor_debian·2018·CVSS 9.1
CVE-2018-12713 [CRITICAL] CVE-2018-12713: gimp - GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, ...
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.0.0~RC1-4)
sid: resolved (fixed in 3.0.0~RC1-4)
trixie: resolved (fixed in 3.0.0~RC1-4)
GHSA
GHSA-hcxp-87ww-ww9m: GIMP through 2
ghsa_unreviewed·2022-05-13
CVE-2018-12713 [CRITICAL] GHSA-hcxp-87ww-ww9m: GIMP through 2
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.
OSV
CVE-2018-12713: GIMP through 2
osv·2018-06-24·CVSS 9.1
CVE-2018-12713 [CRITICAL] CVE-2018-12713: GIMP through 2
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12713 gimp: privilege escalation in gimp_write_and_read_file function in app/tests/test-xcf.c [fedora-all]
bugzilla·2018-06-27·CVSS 9.1
CVE-2018-12713 [CRITICAL] CVE-2018-12713 gimp: privilege escalation in gimp_write_and_read_file function in app/tests/test-xcf.c [fedora-all]
CVE-2018-12713 gimp: privilege escalation in gimp_write_and_read_file function in app/tests/test-xcf.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2018-12713 gimp: predictable temporary file name in test-xcf.c unit test
bugzilla·2018-06-27·CVSS 9.1
CVE-2018-12713 [CRITICAL] CVE-2018-12713 gimp: predictable temporary file name in test-xcf.c unit test
CVE-2018-12713 gimp: predictable temporary file name in test-xcf.c unit test
A flaw was found in GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was intended to be private.
References:
https://gitlab.gnome.org/GNOME/gimp/issues/1689
Patch:
https://github.com/GNOME/gimp/commit/c21eff4b031acb04fb4dfce8bd5fdfecc2b6524f
Discussion:
Created gimp tracking bugs for this issue:
Affects: fedora-all [bug 1595820]
---
Statement:
This issue did affect the versions of gimp as shipped with Red Hat Enterprise Linux 7. However, as this is an issue in a
2018-06-24
Published