- What: Multiple vulnerabilities have been discovered in GIMP.
- Impact: A remote attacker can perform a denial of service attack by tricking a user into opening a specially crafted XCF file.
Main Vulnerability Database SB2022060209 SB2022060209 - Multiple vulnerabilities in Gimp Published: June 2, 2022 Updated: August 23, 2022 Security Bulletin ID SB2022060209 Severity Low Patch available YES Number of vulnerabilities 2 Exploitation vector Remote access Highest impact Denial of service Breakdown by Severity Low Medium High Critical Description This security bulletin contains information about 2 secuirty vulnerabilities. 1) Buffer overflow (CVE-ID: CVE-2022-30067) The vulnerability allows a remote attacker to perform a denial of service attack. The vulnerability exists due to a boundary error in GIMP. A remote attacker can trick the victim into opening a specially crafted XCF file, trigger classic buffer overflow and perform a denial of service attack. 2) Improper Handling of Exceptional Conditions (CVE-ID: CVE-2022-32990) The vulnerability allows a remote attacker to perform a denial of service (DoS) attack. The vulnerability exists due to unhandled exception within the gimp_layer_invalidate_boundary() function. A remote attacker can trick the victim to open a specially crafted XCF file and crash the application. Remediation Install update from vendor's website. References https://gitlab.gnome.org/GNOME/gimp/-/issues/8120 https://bugzilla.redhat.com/show_bug.cgi?id=2087591 https://gitlab.gnome.org/GNOME/gimp/-/issues/8230