Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted KiSS palette file, which triggers an "invalid free."
References
Configurations
History
No history.
Information
Published : 2012-08-25 10:29
Updated : 2025-04-11 00:51
NVD link : CVE-2012-3403
Mitre link : CVE-2012-3403
CVE.ORG link : CVE-2012-3403
JSON object : View
Products Affected
gimp
- gimp
CWE
CWE-787
Out-of-bounds Write