GIMP CVE-2017-17789 Heap Buffer Overflow Vulnerability



GIMP is prone to a heap-based buffer-overflow vulnerability because it fails to properly bounds check user-supplied input.

Successfully exploiting this issue may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.

GIMP 2.8.22 is vulnerable; other versions may also be affected.

Information

Bugtraq ID: 102898
Class: Boundary Condition Error
CVE: CVE-2017-17789

Remote: Yes
Local: No
Published: Dec 20 2017 12:00AM
Updated: Dec 20 2017 12:00AM
Credit: Hanno Böck
Vulnerable: GIMP GIMP 2.8.22


Not Vulnerable:

Exploit


The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.


Related Posts