CVE-2012-3481

Description

Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.809

Associated Vulnerability

VulnerabilityOS Platform
Upgrade gimp 2.8.0 to latest versionWindows
Multiple Vulnerabilities are affected in GIMP 2.2.14Windows
Multiple Vulnerabilities are affected in GIMP 2.6.7Windows
Multiple Vulnerabilities are affected in GIMP 2.6.11Windows
Multiple Vulnerabilities are affected in GIMP 2.6.8Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3402,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.2Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.1Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.2Windows
Multiple Vulnerabilities are affected in GIMP 2.6.1Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481,CVE-2012-4245 are affected in GIMP 2.6.12Windows
Vulnerabilities CVE-2012-2763,CVE-2012-3403,CVE-2012-3481,CVE-2012-4245 are affected in GIMP 2.6.13Windows
Multiple Vulnerabilities are affected in GIMP 2.6.6Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.0Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.3Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.4Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.5Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.6Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.4.7Windows
Multiple Vulnerabilities are affected in GIMP 2.6.0Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481,CVE-2012-4245 are affected in GIMP 2.6.10Windows
Multiple Vulnerabilities are affected in GIMP 2.6.2Windows
Multiple Vulnerabilities are affected in GIMP 2.6.3Windows
Multiple Vulnerabilities are affected in GIMP 2.6.4Windows
Multiple Vulnerabilities are affected in GIMP 2.6.5Windows
Multiple Vulnerabilities are affected in GIMP 2.6.9Windows
Vulnerabilities CVE-2012-3403,CVE-2012-3481 are affected in GIMP 2.8.0-rc1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)
PATCH-338143GIMP (2.10.38)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234