Vulnerabilities > CVE-2007-3741 - Unspecified vulnerability in GNU Gimp

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
gnu
nessus

Summary

The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.

Vulnerable Configurations

Part Description Count
OS
Mandriva
1
Application
Gnu
1

Nessus

  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2007-0513.NASL
    descriptionFrom Red Hat Security Advisory 2007:0513 : Updated gimp packages that fix several security issues are now available for Red Hat Enterprise Linux. This update has been rated as having moderate security impact by the Red Hat Security Response Team. The GIMP (GNU Image Manipulation Program) is an image composition and editing program. Multiple integer overflow and input validation flaws were found in The GIMP
    last seen2020-06-01
    modified2020-06-02
    plugin id67527
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/67527
    titleOracle Linux 3 / 4 / 5 : gimp (ELSA-2007-0513)
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2007-0513.NASL
    descriptionUpdated gimp packages that fix several security issues are now available for Red Hat Enterprise Linux. This update has been rated as having moderate security impact by the Red Hat Security Response Team. The GIMP (GNU Image Manipulation Program) is an image composition and editing program. Multiple integer overflow and input validation flaws were found in The GIMP
    last seen2020-06-01
    modified2020-06-02
    plugin id26203
    published2007-10-03
    reporterThis script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/26203
    titleCentOS 3 / 4 / 5 : gimp (CESA-2007:0513)
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2007-170.NASL
    descriptionMultiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files. (CVE-2006-4519) Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value. (CVE-2007-2949) Victor Stinner has discovered several flaws in file plug-ins using his fuzzyfier tool fusil. Several modified image files cause the plug-ins to crash or consume excessive amounts of memory due to insufficient input validation. Affected plug-ins: bmp, pcx, psd, psp (*.tub). (CVE-2007-3741) Updated packages have been patched to prevent these issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id25947
    published2007-08-28
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/25947
    titleMandrake Linux Security Advisory : gimp (MDKSA-2007:170)
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2007-0513.NASL
    descriptionUpdated gimp packages that fix several security issues are now available for Red Hat Enterprise Linux. This update has been rated as having moderate security impact by the Red Hat Security Response Team. The GIMP (GNU Image Manipulation Program) is an image composition and editing program. Multiple integer overflow and input validation flaws were found in The GIMP
    last seen2020-06-01
    modified2020-06-02
    plugin id26189
    published2007-09-26
    reporterThis script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/26189
    titleRHEL 2.1 / 3 / 4 / 5 : gimp (RHSA-2007:0513)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20070926_GIMP_ON_SL5_X.NASL
    descriptionMultiple integer overflow and input validation flaws were found in The GIMP
    last seen2020-06-01
    modified2020-06-02
    plugin id60256
    published2012-08-01
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/60256
    titleScientific Linux Security Update : gimp on SL5.x, SL4.x, SL3.x i386/x86_64

Oval

accepted2013-04-29T04:01:37.390-04:00
classvulnerability
contributors
  • nameAharon Chernin
    organizationSCAP.com, LLC
  • nameDragos Prisaca
    organizationG2, Inc.
definition_extensions
  • commentThe operating system installed on the system is Red Hat Enterprise Linux 3
    ovaloval:org.mitre.oval:def:11782
  • commentCentOS Linux 3.x
    ovaloval:org.mitre.oval:def:16651
  • commentThe operating system installed on the system is Red Hat Enterprise Linux 4
    ovaloval:org.mitre.oval:def:11831
  • commentCentOS Linux 4.x
    ovaloval:org.mitre.oval:def:16636
  • commentOracle Linux 4.x
    ovaloval:org.mitre.oval:def:15990
  • commentThe operating system installed on the system is Red Hat Enterprise Linux 5
    ovaloval:org.mitre.oval:def:11414
  • commentThe operating system installed on the system is CentOS Linux 5.x
    ovaloval:org.mitre.oval:def:15802
  • commentOracle Linux 5.x
    ovaloval:org.mitre.oval:def:15459
descriptionThe (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.
familyunix
idoval:org.mitre.oval:def:10099
statusaccepted
submitted2010-07-09T03:56:16-04:00
titleThe (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.
version28

Redhat

advisories
bugzilla
id248053
titleCVE-2007-3741 Gimp image loader multiple input validation flaws
oval
OR
  • commentRed Hat Enterprise Linux must be installed
    ovaloval:com.redhat.rhba:tst:20070304026
  • AND
    • commentRed Hat Enterprise Linux 4 is installed
      ovaloval:com.redhat.rhba:tst:20070304025
    • OR
      • AND
        • commentgimp-devel is earlier than 1:2.0.5-7.0.7.el4
          ovaloval:com.redhat.rhsa:tst:20070513001
        • commentgimp-devel is signed with Red Hat master key
          ovaloval:com.redhat.rhsa:tst:20060598004
      • AND
        • commentgimp is earlier than 1:2.0.5-7.0.7.el4
          ovaloval:com.redhat.rhsa:tst:20070513003
        • commentgimp is signed with Red Hat master key
          ovaloval:com.redhat.rhsa:tst:20060598002
  • AND
    • commentRed Hat Enterprise Linux 5 is installed
      ovaloval:com.redhat.rhba:tst:20070331005
    • OR
      • AND
        • commentgimp-devel is earlier than 2:2.2.13-2.0.7.el5
          ovaloval:com.redhat.rhsa:tst:20070513006
        • commentgimp-devel is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhsa:tst:20070343007
      • AND
        • commentgimp-libs is earlier than 2:2.2.13-2.0.7.el5
          ovaloval:com.redhat.rhsa:tst:20070513008
        • commentgimp-libs is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhsa:tst:20070343009
      • AND
        • commentgimp is earlier than 2:2.2.13-2.0.7.el5
          ovaloval:com.redhat.rhsa:tst:20070513010
        • commentgimp is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhsa:tst:20070343011
rhsa
idRHSA-2007:0513
released2008-01-07
severityModerate
titleRHSA-2007:0513: gimp security update (Moderate)
rpms
  • gimp-1:1.2.1-7.8.el2_1
  • gimp-1:1.2.3-20.9.el3
  • gimp-1:2.0.5-7.0.7.el4
  • gimp-2:2.2.13-2.0.7.el5
  • gimp-debuginfo-1:2.0.5-7.0.7.el4
  • gimp-debuginfo-2:2.2.13-2.0.7.el5
  • gimp-devel-1:1.2.1-7.8.el2_1
  • gimp-devel-1:1.2.3-20.9.el3
  • gimp-devel-1:2.0.5-7.0.7.el4
  • gimp-devel-2:2.2.13-2.0.7.el5
  • gimp-libs-2:2.2.13-2.0.7.el5
  • gimp-perl-1:1.2.1-7.8.el2_1
  • gimp-perl-1:1.2.3-20.9.el3