Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.831412
Categoría:Mandrake Local Security Checks
Título:Mandriva Update for gimp MDVSA-2011:103 (gimp)
Resumen:The remote host is missing an update for the 'gimp'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'gimp'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Multiple vulnerabilities was discovered and fixed in gimp:

Stack-based buffer overflow in the 'LIGHTING EFFECTS' & 'LIGHT' plugin in
GIMP 2.6.11 allows user-assisted remote attackers to cause a denial
of service (application crash) or possibly execute arbitrary code
via a long Position field in a plugin configuration file. NOTE:
it may be uncommon to obtain a GIMP plugin configuration file from
an untrusted source that is separate from the distribution of the
plugin itself (CVE-2010-4540).

Stack-based buffer overflow in the SPHERE DESIGNER plugin in GIMP
2.6.11 allows user-assisted remote attackers to cause a denial of
service (application crash) or possibly execute arbitrary code via a
long Number of lights field in a plugin configuration file. NOTE:
it may be uncommon to obtain a GIMP plugin configuration file from
an untrusted source that is separate from the distribution of the
plugin itself (CVE-2010-4541).

Stack-based buffer overflow in the GFIG plugin in GIMP 2.6.11
allows user-assisted remote attackers to cause a denial of service
(application crash) or possibly execute arbitrary code via a long
Foreground field in a plugin configuration file. NOTE: it may be
uncommon to obtain a GIMP plugin configuration file from an untrusted
source that is separate from the distribution of the plugin itself
(CVE-2010-4542).

Heap-based buffer overflow in the read_channel_data function in
file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows
remote attackers to cause a denial of service (application crash)
or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE
compression) image file that begins a long run count at the end of
the image (CVE-2010-4543, CVE-2011-1782).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. The updated packages have been patched to correct these issues.

Affected Software/OS:
gimp on Mandriva Linux 2009.0,
Mandriva Linux 2009.0/X86_64,
Mandriva Linux 2010.1,
Mandriva Linux 2010.1/X86_64,
Mandriva Enterprise Server 5,
Mandriva Enterprise Server 5/X86_64

Solution:
Please Install the Updated Packages.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-4540
42771
http://secunia.com/advisories/42771
44750
http://secunia.com/advisories/44750
48236
http://secunia.com/advisories/48236
50737
http://secunia.com/advisories/50737
70282
http://osvdb.org/70282
ADV-2011-0016
http://www.vupen.com/english/advisories/2011/0016
DSA-2426
http://www.debian.org/security/2012/dsa-2426
GLSA-201209-23
http://security.gentoo.org/glsa/glsa-201209-23.xml
MDVSA-2011:103
http://www.mandriva.com/security/advisories?name=MDVSA-2011:103
RHSA-2011:0838
http://www.redhat.com/support/errata/RHSA-2011-0838.html
RHSA-2011:0839
http://www.redhat.com/support/errata/RHSA-2011-0839.html
SUSE-SR:2011:005
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
[oss-security] 20110103 CVE request for buffer overflows in gimp
http://openwall.com/lists/oss-security/2011/01/03/2
[oss-security] 20110104 Re: CVE request for buffer overflows in gimp
http://openwall.com/lists/oss-security/2011/01/04/7
gimp-lightning-effects-bo(64582)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64582
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497
https://bugzilla.redhat.com/show_bug.cgi?id=666793
Common Vulnerability Exposure (CVE) ID: CVE-2010-4541
70281
http://osvdb.org/70281
RHSA-2011:0837
http://www.redhat.com/support/errata/RHSA-2011-0837.html
gimp-sphere-designer-bo(64581)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64581
Common Vulnerability Exposure (CVE) ID: CVE-2010-4542
70283
http://osvdb.org/70283
Common Vulnerability Exposure (CVE) ID: CVE-2010-4543
70284
http://osvdb.org/70284
Common Vulnerability Exposure (CVE) ID: CVE-2011-1782
https://bugzilla.redhat.com/show_bug.cgi?id=704512
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.