Upstream information
Description
Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted KiSS palette file, which triggers an "invalid free."NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 763595, 775433 SUSE Security Advisories:- SUSE-SU-2012:1027-1, published Thu, 23 Aug 2012 16:08:24 +0200 (CEST)
- SUSE-SU-2012:1029-1, published Thu, 23 Aug 2012 16:08:28 +0200 (CEST)
- openSUSE-SU-2012:1080-1, published Mon, 3 Sep 2012 11:09:17 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE SDK 10 SP4 for IBM iSeries and IBM pSeries SLE SDK 10 SP4 for IBM zSeries SLE SDK 10 SP4 for IPF SLE SDK 10 SP4 for X86-64 SLE SDK 10 SP4 for x86 SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP4 for x86 |
| sled10-sp4.x86 sled10-sp4.x86-64 sle10-sp4-sdk.x86-64 sle10-sp4-sdk.s390x sle10-sp4-sdk.ppc sle10-sp4-sdk.ia64 sle10-sp4-sdk.x86 ZYPP Patch Nr: 8251 |
| SLE 11 SP1 DEBUGINFO |
| sle11-sp1-sdk.ppc sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sle11-sp1-sdk.x86 sled11-sp2.x86-64 sle11-sp2-sdk.ia64 sle11-sp2-sdk.x86-64 sle11-sp2-sdk.ppc sle11-sp1-sdk.ia64 sle11-sp2-sdk.x86 sled11-sp2.x86 sled11-sp1.x86-64 sled11-sp1.x86 sle11-sp2-sdk.s390x SAT Patch Nr: 6683 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp1-sdk.ppc sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sle11-sp1-sdk.x86 sled11-sp2.x86-64 sle11-sp2-sdk.ia64 sle11-sp2-sdk.x86-64 sle11-sp2-sdk.ppc sle11-sp1-sdk.ia64 sle11-sp2-sdk.x86 sled11-sp2.x86 sled11-sp1.x86-64 sled11-sp1.x86 sle11-sp2-sdk.s390x SAT Patch Nr: 6683 |
| SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Desktop 11 SP2 |
| sle11-sp1-sdk.ppc sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sle11-sp1-sdk.x86 sled11-sp2.x86-64 sle11-sp2-sdk.ia64 sle11-sp2-sdk.x86-64 sle11-sp2-sdk.ppc sle11-sp1-sdk.ia64 sle11-sp2-sdk.x86 sled11-sp2.x86 sled11-sp1.x86-64 sled11-sp1.x86 sle11-sp2-sdk.s390x SAT Patch Nr: 6683 |
