SCIENTIFIC-LINUX-ERRATA Archives

June 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Fri, 3 Jun 2011 13:32:41 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (49 lines)
Synopsis:    Moderate: gimp security update
Issue Date:  2011-05-31
CVE Numbers: CVE-2010-4540
              CVE-2010-4541
              CVE-2010-4542
              CVE-2010-4543


The GIMP (GNU Image Manipulation Program) is an image composition and
editing program.

A heap-based buffer overflow flaw was found in the GIMP's Paint Shop Pro
(PSP) image file plug-in. An attacker could create a specially-crafted 
PSP image file that, when opened, could cause the PSP plug-in to crash 
or, potentially, execute arbitrary code with the privileges of the user 
running the GIMP. (CVE-2010-4543)

A stack-based buffer overflow flaw was found in the GIMP's Lightning,
Sphere Designer, and Gfig image filters. An attacker could create a
specially-crafted Lightning, Sphere Designer, or Gfig filter 
configuration file that, when opened, could cause the relevant plug-in 
to crash or, potentially, execute arbitrary code with the privileges of 
the user running the GIMP. (CVE-2010-4540, CVE-2010-4541, CVE-2010-4542)

Users of the GIMP are advised to upgrade to these updated packages, 
which contain backported patches to correct these issues. The GIMP must 
be restarted for the update to take effect.

SL6:
   x86_64
      gimp-libs-2.6.9-4.el6_1.1.x86_64.rpm
      gimp-libs-2.6.9-4.el6_1.1.i686.rpm
      gimp-help-browser-2.6.9-4.el6_1.1.x86_64.rpm
      gimp-devel-tools-2.6.9-4.el6_1.1.x86_64.rpm
      gimp-devel-2.6.9-4.el6_1.1.x86_64.rpm
      gimp-devel-2.6.9-4.el6_1.1.i686.rpm
      gimp-debuginfo-2.6.9-4.el6_1.1.x86_64.rpm
      gimp-debuginfo-2.6.9-4.el6_1.1.i686.rpm
      gimp-2.6.9-4.el6_1.1.x86_64.rpm
   i386
      gimp-libs-2.6.9-4.el6_1.1.i686.rpm
      gimp-help-browser-2.6.9-4.el6_1.1.i686.rpm
      gimp-devel-tools-2.6.9-4.el6_1.1.i686.rpm
      gimp-devel-2.6.9-4.el6_1.1.i686.rpm
      gimp-debuginfo-2.6.9-4.el6_1.1.i686.rpm
      gimp-2.6.9-4.el6_1.1.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2