REDHAT-BUG-2496583: Medium severity Gnome GIMP vulnerability
https://gitlab.gnome.org/GNOME/gimp/-/workitems/16493
PlayStation TIM loader computes CLUT size as guint clutsize = numcolors numcluts; Both operands are gushort. After integer promotion, 65535 65535 = 4,294,836,225 > INTMAX → undefined behavior. UBSan-detected; plug-in aborts.
File: plug-ins/common/file-tim.c:486 Version: GIMP 3.2.4
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
gimp 3.2.4to a version that resolves this vulnerability.Fixed in 3.2.4
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2496583?
The severity of REDHAT-BUG-2496583 is medium, rated at 4.
How do I fix REDHAT-BUG-2496583?
To fix REDHAT-BUG-2496583, update to the latest version of Gnome GIMP that addresses this vulnerability.
What type of vulnerability is REDHAT-BUG-2496583?
REDHAT-BUG-2496583 is a vulnerability that leads to undefined behavior due to integer overflow in the PlayStation TIM loader.
What happens if I do not address REDHAT-BUG-2496583?
If REDHAT-BUG-2496583 is not addressed, it may cause the GIMP plug-in to abort unexpectedly.
Is there a known exploit for REDHAT-BUG-2496583?
Currently, there is no publicly known exploit for REDHAT-BUG-2496583.