Security Vulnerability in GIMP(1) May Lead to Denial of Service (DoS) or Execution of Arbitrary Code |
|
| Category : | Security |
| Release Phase : | Resolved |
| Product : | Solaris 9 Operating System Solaris 10 Operating System
|
| Bug Id : | 6451577
|
| Date of Workaround Release : | 20-NOV-2006
|
| Date of Resolved Release : | 08-Sep-2008
|
A security vulnerability in the GNU Image Manipulation Program (GIMP) (see below for details)
1. Impact
A security vulnerability in the
GNU Image Manipulation Program (GIMP) may allow a remote unprivileged
user to cause a Denial of Service (DoS) to the GIMP application or
execute arbitrary code with the privileges of a local user when that
local user loads an XCF image file supplied by an untrusted source.
This issue is described in the following document:
2. Contributing Factors
This issue can occur in the following releases:
SPARC Platform
x86 Platform
Note: Solaris 8 and Solaris 9 on the SPARC Platform and Solaris 8 on the x86 Platform are not affected by this issue.
3.
Symptoms
There are no reliable symptoms that would show the described issues have been exploited.
4. Workaround
To avoid this issue, do not load images from untrusted sources.
5. Resolution
This issue is addressed in the following releases:
SPARC Platform
x86 Platform
For more information on Security Sun Alerts, see Technical Instruction ID 213557
This Sun Alert notification
is being provided to you on an "AS IS" basis. This Sun Alert
notification may contain information provided by third parties. The
issues described in this Sun Alert notification may or may not impact
your system(s). Sun makes no representations, warranties, or guarantees
as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS
OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY
DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN SHALL
IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE,
OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE
THE INFORMATION CONTAINED HEREIN. This Sun Alert notification contains
Sun proprietary and confidential information. It is being provided to
you pursuant to the provisions of your agreement to purchase services
from Sun, or, if you do not have such an agreement, the Sun.com Terms
of Use. This Sun Alert notification may only be used for the purposes
contemplated by these agreements.
Copyright 2000-2008 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved.
AttachmentsThis solution has no attachment