eSikker.dk

Sårbarhed Detalje Syn
Legend : critical high medium low other
id 43144
Risiko other
Familie Mandriva Local Security Checks
Kategori infos
Navn MDVSA-2009:296-1: gimp
Sammenfatning Check for the version of the gimp package
Beskrivelse Synopsis :

The remote host is missing the patch for the advisory MDVSA-2009:296-1 (gimp).

Description :

A vulnerability was discovered and corrected in gimp:
Integer overflow in the ReadImage function in
plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers
to execute arbitrary code via a BMP file with crafted width and height
values that trigger a heap-based buffer overflow (CVE-2009-1570).
This update provides a solution to this vulnerability.
Update:
Packages for 2008.0 are being provided due to extended support for
Corporate products.

See also :

http://wwwnew.mandriva.com/security/advisories?name=MDVSA-2009:296-1

Solution :

Apply the newest security patches from Mandriva.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVE CVE-2009-1570
Bugtraq NOBID
Copyright (C) 2009 Tenable Network Security
58
PCbix kan findes hos twitter PC håndværkeren - Er din PC i stykker? Banken lukkede din netbank? Har din PC virus? Ekstern USB harddisk kasse med eller uden harddisk. Lillekilde i Valby Studiehuset Ole Opfinder Hosted by FLIFL
design by Pingvino