CVE-2012-5576

Publication date 27 November 2012

Last updated 24 July 2024


Ubuntu priority

Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
gimp 12.10 quantal
Fixed 2.8.2-1ubuntu1.1
12.04 LTS precise
Fixed 2.6.12-1ubuntu1.2
11.10 oneiric
Fixed 2.6.11-2ubuntu4.2
10.04 LTS lucid
Fixed 2.6.8-2ubuntu1.6
8.04 LTS hardy Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
gimp

References

Related Ubuntu Security Notices (USN)

Other references