Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24540
HistoryApr 10, 2020 - 12:56 a.m.

Arbitrary Code Execution

2020-04-1000:56:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.007 Low

EPSS

Percentile

80.3%

gimp is vulnerable to arbitrary code execution. A stack-based buffer overflow flaw was found in the GIMP’s Lightning, Sphere Designer, and Gfig image filters. An attacker could create a specially-crafted Lightning, Sphere Designer, or Gfig filter configuration file that, when opened, could cause the relevant plug-in to crash or, potentially, execute arbitrary code with the privileges of the user running the GIMP.

CPENameOperatorVersion
gimpeq2.2.13__2.el5
gimpeq2.2.13__2.el5

References