Ubuntu 10.04 LTS / 11.04 / 11.10 / 12.04 LTS : gimp vulnerabilities (USN-1559-1)

Ubuntu Security Notice (C) 2012-2016 Canonical, Inc. / NASL script (C) 2012-2016 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing a security-related patch.

Description :

Joseph Sheridan discovered that GIMP incorrectly handled certain
malformed headers in FIT files. If a user were tricked into opening a
specially crafted FIT image file, an attacker could cause GIMP to
crash. (CVE-2012-3236)

Murray McAllister discovered that GIMP incorrectly handled malformed
KiSS palette files. If a user were tricked into opening a specially
crafted KiSS palette file, an attacker could cause GIMP to crash, or
possibly execute arbitrary code with the user's privileges.
(CVE-2012-3403)

Matthias Weckbecker discovered that GIMP incorrectly handled malformed
GIF image files. If a user were tricked into opening a specially
crafted GIF image file, an attacker could cause GIMP to crash, or
possibly execute arbitrary code with the user's privileges.
(CVE-2012-3481).

Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

Solution :

Update the affected gimp package.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.9
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 62037 ()

Bugtraq ID: 54246
55101

CVE ID: CVE-2012-3236
CVE-2012-3403
CVE-2012-3481

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial