vendor:
GIMP
by:
Joseph Sheridan
7,5
CVSS
HIGH
Denial of Service (DoS)
119
CWE
Product Name: GIMP
Affected Version From: GIMP <= 2.8.0
Affected Version To: GIMP 2.8.0
Patch Exists: YES
Related CWE: CVE-2012-3236
CPE: a:gimp:gimp
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2012
GIMP File Handling DoS
There is a file handling DoS in GIMP (the GNU Image Manipulation Program) for the 'fit' file format affecting all versions (Windows and Linux) up to and including 2.8.0. A file in the fit format with a malformed 'XTENSION' header will cause a crash in the GIMP program.
Mitigation:
Upgrade to GIMP 2.8.1 or later.