Bugzilla – Bug 768376
VUL-1: CVE-2012-3236: gimp FIT file DoS
Last modified: 2021-08-11 09:08:33 UTC
Your friendly security team received the following report via vendor-sec. Please respond ASAP. This issue is not public yet, please keep any information about it inside SUSE. Note that build.opensuse.org *cannot* be used to prepare embargoed updates. CVE-2012-3236 Specially crafted "fit" files with a malformed 'XTENSION' can crash GIMP. http://www.reactionpenetrationtesting.co.uk/advisories/FIT-handling-DoS.html
simply crash on NULL is not really a security issue in the context of GIMP. Fix for Factory sufficient when public.
This is already public: http://git.gnome.org/browse/gimp/commit/?h=gimp-2-8&id=0474376d234bc3d0901fd5e86f89d778a6473dd8
bugbot adjusting priority
https://bugzilla.gnome.org/show_bug.cgi?id=676804
So should we just go ahead and submit the fix, or do we still wait to wait until Friday?
doesn't make sense to wait with a public bug report of course but the reporter hasn't answered the question yet. It's just a NULL deref so no risk in waiting though.
Since I'm unsure I'll have time to deal with it later this week, I went ahead and submitted to G:A: sr#125930.
https://build.opensuse.org/request/show/125934 Hrm, I guess there's no need to reassign to security-team since this is Factory-only as per comment 3, so closing.
This is an autogenerated message for OBS integration: This bug (768376) was mentioned in https://build.opensuse.org/request/show/603017 Factory / gimp
This is an autogenerated message for OBS integration: This bug (768376) was mentioned in https://build.opensuse.org/request/show/605190 15.0 / gimp