Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.69678
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Security Advisory MDVSA-2011:103 (gimp)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to gimp
announced via advisory MDVSA-2011:103.

Multiple vulnerabilities was discovered and fixed in gimp:

Stack-based buffer overflow in the 'LIGHTING EFFECTS > LIGHT' plugin in
GIMP 2.6.11 allows user-assisted remote attackers to cause a denial
of service (application crash) or possibly execute arbitrary code
via a long Position field in a plugin configuration file. NOTE:
it may be uncommon to obtain a GIMP plugin configuration file from
an untrusted source that is separate from the distribution of the
plugin itself (CVE-2010-4540).

Stack-based buffer overflow in the SPHERE DESIGNER plugin in GIMP
2.6.11 allows user-assisted remote attackers to cause a denial of
service (application crash) or possibly execute arbitrary code via a
long Number of lights field in a plugin configuration file. NOTE:
it may be uncommon to obtain a GIMP plugin configuration file from
an untrusted source that is separate from the distribution of the
plugin itself (CVE-2010-4541).

Stack-based buffer overflow in the GFIG plugin in GIMP 2.6.11
allows user-assisted remote attackers to cause a denial of service
(application crash) or possibly execute arbitrary code via a long
Foreground field in a plugin configuration file. NOTE: it may be
uncommon to obtain a GIMP plugin configuration file from an untrusted
source that is separate from the distribution of the plugin itself
(CVE-2010-4542).

Heap-based buffer overflow in the read_channel_data function in
file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows
remote attackers to cause a denial of service (application crash)
or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE
compression) image file that begins a long run count at the end of
the image (CVE-2010-4543, CVE-2011-1782).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php\?cPath=149\&products_id=490

The updated packages have been patched to correct these issues.

Affected: 2009.0, 2010.1, Enterprise Server 5.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2011:103

Risk factor : Critical

CVSS Score:
9.3

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-4540
42771
http://secunia.com/advisories/42771
44750
http://secunia.com/advisories/44750
48236
http://secunia.com/advisories/48236
50737
http://secunia.com/advisories/50737
70282
http://osvdb.org/70282
ADV-2011-0016
http://www.vupen.com/english/advisories/2011/0016
DSA-2426
http://www.debian.org/security/2012/dsa-2426
GLSA-201209-23
http://security.gentoo.org/glsa/glsa-201209-23.xml
MDVSA-2011:103
http://www.mandriva.com/security/advisories?name=MDVSA-2011:103
RHSA-2011:0838
http://www.redhat.com/support/errata/RHSA-2011-0838.html
RHSA-2011:0839
http://www.redhat.com/support/errata/RHSA-2011-0839.html
SUSE-SR:2011:005
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
[oss-security] 20110103 CVE request for buffer overflows in gimp
http://openwall.com/lists/oss-security/2011/01/03/2
[oss-security] 20110104 Re: CVE request for buffer overflows in gimp
http://openwall.com/lists/oss-security/2011/01/04/7
gimp-lightning-effects-bo(64582)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64582
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497
https://bugzilla.redhat.com/show_bug.cgi?id=666793
Common Vulnerability Exposure (CVE) ID: CVE-2010-4541
70281
http://osvdb.org/70281
RHSA-2011:0837
http://www.redhat.com/support/errata/RHSA-2011-0837.html
gimp-sphere-designer-bo(64581)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64581
Common Vulnerability Exposure (CVE) ID: CVE-2010-4542
70283
http://osvdb.org/70283
Common Vulnerability Exposure (CVE) ID: CVE-2010-4543
70284
http://osvdb.org/70284
Common Vulnerability Exposure (CVE) ID: CVE-2011-1782
https://bugzilla.redhat.com/show_bug.cgi?id=704512
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.