Bug 775433 - VUL-0: CVE-2012-3403: gimp: Heap buffer overflow when loading external palette files
Summary: VUL-0: CVE-2012-3403: gimp: Heap buffer overflow when loading external palett...
Status: RESOLVED FIXED
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Critical
Target Milestone: ---
Deadline: 2012-08-17
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp1:48751
Keywords:
Depends on:
Blocks:
 
Reported: 2012-08-10 13:40 UTC by Matthias Weckbecker
Modified: 2015-02-18 22:19 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Weckbecker 2012-08-10 13:40:07 UTC
A heap overflow in gimp's CEL plug-in was found which could cause a Denial of
Service (application crash) or, potentially, allow the execution of arbitrary
code via specially crafted image files.

Note:
-----
This issue is NOT public yet. Please keep any information inside SUSE and do
NOT use the open build service to prepare fixed packages.

Embargo date will be: Thursday, 2012-08-16, 12:00 UTC time.
Comment 2 Swamp Workflow Management 2012-08-10 14:19:34 UTC
The SWAMPID for this issue is 48680.
This issue was rated as important.
Please submit fixed packages until 2012-08-17.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 3 Mu Lei 2012-08-15 07:15:28 UTC
SLE-11 done => rid 21287
Comment 5 Mu Lei 2012-08-16 03:09:48 UTC
openSUSE reqms id 130993
Comment 13 Mu Lei 2012-08-22 08:38:20 UTC
done.
openSUSE-12.1 reqms id 131341
openSUSE-11.4 reqms id 131342
Comment 14 Swamp Workflow Management 2012-08-23 10:24:35 UTC
Update released for: gimp, gimp-branding-upstream, gimp-debuginfo, gimp-debugsource, gimp-devel, gimp-doc, gimp-lang, gimp-plugins-python
Products:
SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-DESKTOP 11-SP1-FOR-SP2 (i386, x86_64)
SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64)
SLE-SDK 11-SP1-FOR-SP2 (i386, ia64, ppc64, s390x, x86_64)
Comment 15 Mu Lei 2012-08-24 08:30:15 UTC
131342 was revoked since we shouldn't use reqms.

here is the new one:
openSUSE-11.4 request id #131467
Comment 16 Matthias Weckbecker 2012-08-24 13:26:57 UTC
Thanks, the next one would be 12.1.
Comment 17 Mu Lei 2012-08-27 03:31:25 UTC
131341 was revoked.
new openSUSE-12.1 request id #131726
Comment 18 Marcus Meissner 2012-08-30 07:33:40 UTC
all submitted, back to security
Comment 19 Marcus Meissner 2012-08-30 14:59:46 UTC
needinfo ok
Comment 20 Sebastian Krahmer 2012-09-03 08:29:58 UTC
done
Comment 21 Swamp Workflow Management 2012-09-03 09:09:58 UTC
openSUSE-SU-2012:1080-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 724628,763595,769565,775433
CVE References: CVE-2012-2763,CVE-2012-3236,CVE-2012-3403,CVE-2012-3481
Sources used:
openSUSE 12.1 (src):    gimp-2.6.11-28.26.1
openSUSE 11.4 (src):    gimp-2.6.11-13.58.1
Comment 22 Bernhard Wiedemann 2012-09-07 13:00:55 UTC
This is an autogenerated message for OBS integration:
This bug (775433) was mentioned in
https://build.opensuse.org/request/show/133225 Evergreen:11.2 / gimp
Comment 23 Bernhard Wiedemann 2012-09-11 12:00:37 UTC
This is an autogenerated message for OBS integration:
This bug (775433) was mentioned in
https://build.opensuse.org/request/show/133620 Evergreen:11.2 / gimp