UBUNTU-CVE-2017-17786
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-17786
UBUNTU-CVE-2017-17786
Summary:
Details: In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
References: https://ubuntu.com/security/CVE-2017-17786, https://bugzilla.gnome.org/show_bug.cgi?id=739134, https://git.gnome.org/browse/gimp/commit/?id=674b62ad45b6579ec6d7923dc3cb1ef4e8b5498b, https://git.gnome.org/browse/gimp/commit/?id=8ea316667c8a3296bce2832b3986b58d0fdfc077, https://git.gnome.org/browse/gimp/commit/?h=gimp-2-8&id=ef9c821fff8b637a2178eab1c78cae6764c50e12, https://git.gnome.org/browse/gimp/commit/?h=gimp-2-8&id=22e2571c25425f225abdb11a566cc281fca6f366, http://www.openwall.com/lists/oss-security/2017/12/19/5, https://ubuntu.com/security/notices/USN-3539-1, https://www.cve.org/CVERecord?id=CVE-2017-17786
Affected packages
Package
Name: gimp
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
