CVE-2006-3404
gimp - buffer overflow
EPSS 5.0%
描述
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.
如何修補 CVE-2006-3404
要修補 CVE-2006-3404,請將受影響套件升級到下列已修補版本。
- Debian/gimp—升級至 2.2.11-3.1 或更新版本
- Debian/gimp—升級至 2.2.6-1sarge1 或更新版本
CVE-2006-3404 正在被利用嗎?
中等 — EPSS 為 5.0%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 2.2.11-3.1
- from 0, < 2.2.6-1sarge1