ALT-PU-2016-1787-1
Closed vulnerabilities
Published: 2016-07-12
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-4994
Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- openSUSE-SU-2016:1727
- openSUSE-SU-2016:1727
- RHSA-2016:2589
- RHSA-2016:2589
- DSA-3612
- DSA-3612
- 91425
- 91425
- 1036226
- 1036226
- SSA:2016-203-01
- SSA:2016-203-01
- USN-3025-1
- USN-3025-1
- https://bugzilla.gnome.org/show_bug.cgi?id=767873
- https://bugzilla.gnome.org/show_bug.cgi?id=767873
- https://git.gnome.org/browse/gimp/commit/?id=e82aaa4b4ee0703c879e35ea9321fff6be3e9b6f
- https://git.gnome.org/browse/gimp/commit/?id=e82aaa4b4ee0703c879e35ea9321fff6be3e9b6f