CVE-2012-3403

Description

Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted KiSS palette file, which triggers an invalid free.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
4.289

Associated Vulnerability

VulnerabilityOS Platform
Upgrade gimp 2.8.0 to latest versionWindows
Multiple Vulnerabilities are affected in GIMP 2.2.14Windows
Multiple Vulnerabilities are affected in GIMP 2.6.7Windows
Multiple Vulnerabilities are affected in GIMP 2.6.11Windows
Multiple Vulnerabilities are affected in GIMP 2.6.8Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3402,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.2Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.1Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.2Windows
Multiple Vulnerabilities are affected in GIMP 2.6.1Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481,CVE-2012-4245 are affected in GIMP 2.6.12Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481,CVE-2012-4245 are affected in GIMP 2.6.13Windows
Multiple Vulnerabilities are affected in GIMP 2.6.6Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.0Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.3Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.4Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.5Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.6Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.7Windows
Multiple Vulnerabilities are affected in GIMP 2.6.0Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481,CVE-2012-4245 are affected in GIMP 2.6.10Windows
Multiple Vulnerabilities are affected in GIMP 2.6.2Windows
Multiple Vulnerabilities are affected in GIMP 2.6.3Windows
Multiple Vulnerabilities are affected in GIMP 2.6.4Windows
Multiple Vulnerabilities are affected in GIMP 2.6.5Windows
Multiple Vulnerabilities are affected in GIMP 2.6.9Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.8.0-rc1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234