PT-2019-17468 · Gimp+2 · Xcftools+2
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xcftools version 1.0.7
Description
An integer overflow vulnerability exists in the
flattenIncrementally function in the xcf2png and xcf2pnm binaries. This vulnerability can occur while calculating the row's allocation size, potentially allowing memory corruption and arbitrary code execution. A victim would need to open a specially crafted XCF file to trigger this issue.Recommendations
For version 1.0.7, consider disabling the
flattenIncrementally function as a temporary workaround until a patch is available. Restrict access to the xcf2png and xcf2pnm binaries to minimize the risk of exploitation. Avoid opening specially crafted XCF files with the affected binaries until the issue is resolved.Exploit
Correção
Memory Corruption
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linuxmint
Ubuntu
Xcftools