Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: Josh Bressers <bressers-H+wXaHxf7aLQT0dZR+AlfA <at> public.gmane.org>
Subject: Re: CVE request for buffer overflows in gimp
Newsgroups: gmane.comp.security.oss.general
Date: Tuesday 4th January 2011 14:04:52 UTC (over 6 years ago)
----- Original Message -----
> Hello Steve, Vendors,
> 
> This one is from the debian bug tracker [1], there are four buffer
> overflows in gimp plugins.
> 
> I am not sure if this would need one CVE or four?
> 
> [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497
> 
> 

I'm going to give this four. We *might* be able to get away with two, but
since they're all in quite different bits of code, I'm betting the affected
versions are different, and it's likely upstream is going to fix these all
at different times in their SCM.

CVE-2010-4540 gimp LIGHTING EFFECTS > LIGHT plugin stack buffer overflow
CVE-2010-4541 gimp SPHERE DESIGNER plugin stack buffer overflow
CVE-2010-4542 gimp GFIG plugin stack buffer overflow
CVE-2010-4543 gimp heap overflow read_channel_data() in file-psp.c

Thanks.

-- 
    JB
 
CD: 4ms