Description
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corruption and potential code execution.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 14 | | =3.0.4-3 || =3.0.4-4 || =3.0.4-5 || =3.0.4-6 || =3.0.4-6.1 || =3.0.4-6.2 || =3.0.6-1 || =3.2.0-1 || =3.2.0~rc2-1 || =3.2.0~rc2-2 || =3.2.0~rc2-3 || =3.2.0~rc2-3.1 || =3.2.0~rc2-3.2 || =3.2.0~rc2-3.3 || =3.2.0~rc3-1 || =3.2.2-1 || >=0 <3.2.4-1 | 3.2.4-1 |
 rpm rhel6 | | - | - |
 rpm rhel7 | | - | - |
 rpm rhel8 | | - | - |
 debian 12 | | =2.10.34-1 || =2.10.34-1+deb12u1 || =2.10.34-1+deb12u10 || =2.10.34-1+deb12u2 || =2.10.34-1+deb12u3 || =2.10.34-1+deb12u4 || =2.10.34-1+deb12u5 || =2.10.34-1+deb12u6 || =2.10.34-1+deb12u7 || =2.10.34-1+deb12u8 || =2.10.34-1+deb12u9 || =2.10.36-1 || =2.10.36-2 || =2.10.36-3 || =2.10.38-1 || =2.10.38-2 || =2.99.10-1 || =2.99.12-1 || =2.99.12-2 || =2.99.14-1 || =2.99.14-2 || =2.99.16-1 || =2.99.16-2 || =2.99.18-1 || =3.0.0-1 || =3.0.0-2 || =3.0.0~rc1-1 || =3.0.0~rc1-3 || =3.0.0~rc1-4 || =3.0.0~rc2-1 || =3.0.0~rc3-1 || =3.0.2-1 || =3.0.2-2 || =3.0.2-3 || =3.0.2-3.1 || =3.0.4-1 || =3.0.4-2 || =3.0.4-3 || =3.0.4-4 || =3.0.4-5 || =3.0.4-6 || =3.0.4-6.1 || =3.0.4-6.2 || =3.0.6-1 || =3.2.0-1 || =3.2.0~rc2-1 || =3.2.0~rc2-2 || =3.2.0~rc2-3 || =3.2.0~rc2-3.1 || =3.2.0~rc2-3.2 || =3.2.0~rc2-3.3 || =3.2.0~rc3-1 || =3.2.2-1 || =3.2.4-1 || =3.2.4-2 || =3.2.4-3 || =3.2.6-1 | - |
 debian 13 | | =3.0.4-3 || =3.0.4-3+deb13u1 || =3.0.4-3+deb13u2 || =3.0.4-3+deb13u3 || =3.0.4-3+deb13u4 || =3.0.4-3+deb13u5 || =3.0.4-3+deb13u6 || =3.0.4-3+deb13u7 || =3.0.4-3+deb13u8 || =3.0.4-3+deb13u9 || >=0 <3.0.4-3+deb13u10 | 3.0.4-3+deb13u10 |