Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.122659
Categoría:Oracle Linux Local Security Checks
Título:Oracle: Security Advisory (ELSA-2007-0513)
Resumen:The remote host is missing an update for the 'gimp' package(s) announced via the ELSA-2007-0513 advisory.
Descripción:Summary:
The remote host is missing an update for the 'gimp' package(s) announced via the ELSA-2007-0513 advisory.

Vulnerability Insight:
[1.2.3-20.9.el3]
- validate bytesperline header field when loading PCX files (#247570)

[1.2.3-20.8.el3]
- reduce GIMP_MAX_IMAGE_SIZE to 2^18 to detect bogus image widths/heights
(#247570)

[1.2.3-20.7.el3]
- replace gimp_error() by gimp_message()/gimp_quit() in a few plugins so
they
don't crash but gracefully exit when encountering error conditions
- fix endianness issues in the PSP plugin to avoid it doing (seemingly)
endless
loops when loading images
- fix endianness issues in the PCX plugin which cause it to not detect
corrupt
images

[1.2.3-20.6.el3]
- add ChangeLog entry to psd-invalid-dimensions patch (#247570)
- validate size values read from files before using them to allocate
memory in
various file plugins (#247570, patch by Mukund Sivaraman and Rapha??l
Quinet,
adapted)
- detect invalid image data when reading files in several plugins (#247570,
patch by Sven Neumann and Rapha??l Quinet, adapted)
- validate size values read from files before using them to allocate
memory in
the PSD and sunras plugins (#247570, patch by Mukund Sivaraman and Sven
Neumann, partly adapted)
- add safeguard to avoid crashes while loading corrupt PSD images (#247570,
patch by Rapha??l Quinet, adapted)
- convert spec file to UTF-8

[1.2.3-20.5.el3]
- use adapted upstream PSD fix by Sven Neumann (#244406)

[1.2.3-20.4.el3]
- refuse to open PSD files with insanely large dimensions (#244406)

Affected Software/OS:
'gimp' package(s) on Oracle Linux 3, Oracle Linux 4, Oracle Linux 5.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2006-4519
BugTraq ID: 24835
http://www.securityfocus.com/bid/24835
Bugtraq: 20070801 FLEA-2007-0038-1 gimp (Google Search)
http://www.securityfocus.com/archive/1/475257/100/0/threaded
Debian Security Information: DSA-1335 (Google Search)
http://www.debian.org/security/2007/dsa-1335
http://security.gentoo.org/glsa/glsa-200707-09.xml
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=551
http://www.mandriva.com/security/advisories?name=MDKSA-2007:170
http://osvdb.org/42139
http://osvdb.org/42140
http://osvdb.org/42141
http://osvdb.org/42142
http://osvdb.org/42143
http://osvdb.org/42144
http://osvdb.org/42145
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10842
http://www.redhat.com/support/errata/RHSA-2007-0513.html
http://www.securitytracker.com/id?1018349
http://secunia.com/advisories/26132
http://secunia.com/advisories/26215
http://secunia.com/advisories/26240
http://secunia.com/advisories/26575
http://secunia.com/advisories/26939
http://www.ubuntu.com/usn/usn-494-1
http://www.vupen.com/english/advisories/2007/2471
XForce ISS Database: gimp-plugins-code-execution(35308)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35308
Common Vulnerability Exposure (CVE) ID: CVE-2007-2949
BugTraq ID: 24745
http://www.securityfocus.com/bid/24745
CERT/CC vulnerability note: VU#399896
http://www.kb.cert.org/vuls/id/399896
http://secunia.com/secunia_research/2007-63/advisory/
http://osvdb.org/37804
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11276
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5772
http://secunia.com/advisories/25677
http://secunia.com/advisories/25949
http://secunia.com/advisories/26044
http://secunia.com/advisories/26384
http://secunia.com/advisories/28114
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.360191
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103170-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201320-1
SuSE Security Announcement: SUSE-SR:2007:015 (Google Search)
http://www.novell.com/linux/security/advisories/2007_15_sr.html
http://www.ubuntu.com/usn/usn-480-1
http://www.vupen.com/english/advisories/2007/2421
http://www.vupen.com/english/advisories/2007/4241
XForce ISS Database: gimp-unpackpixeldata-code-execution(35246)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35246
Common Vulnerability Exposure (CVE) ID: CVE-2007-3741
25424
http://www.securityfocus.com/bid/25424
26575
26939
42128
http://osvdb.org/42128
42129
http://osvdb.org/42129
42130
http://osvdb.org/42130
42131
http://osvdb.org/42131
MDKSA-2007:170
RHSA-2007:0513
oval:org.mitre.oval:def:10099
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10099
CopyrightCopyright (C) 2015 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.