Description
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | =3.0.4-3 || =3.0.4-3+deb13u1 || =3.0.4-3+deb13u10 || =3.0.4-3+deb13u2 || =3.0.4-3+deb13u3 || =3.0.4-3+deb13u4 || =3.0.4-3+deb13u5 || =3.0.4-3+deb13u6 || =3.0.4-3+deb13u7 || =3.0.4-3+deb13u8 || =3.0.4-3+deb13u9 || >=0 <3.0.4-3+deb13u11 | 3.0.4-3+deb13u11 |
 debian 14 | | =3.0.4-3 || =3.0.4-4 || =3.0.4-5 || =3.0.4-6 || =3.0.4-6.1 || =3.0.4-6.2 || =3.0.6-1 || =3.2.0-1 || =3.2.0~rc2-1 || =3.2.0~rc2-2 || =3.2.0~rc2-3 || =3.2.0~rc2-3.1 || =3.2.0~rc2-3.2 || =3.2.0~rc2-3.3 || =3.2.0~rc3-1 || =3.2.2-1 || =3.2.4-1 || =3.2.4-2 || =3.2.4-3 || =3.2.6-1 | - |
 debian 12 | | =2.10.34-1 || =2.10.34-1+deb12u1 || =2.10.34-1+deb12u10 || =2.10.34-1+deb12u2 || =2.10.34-1+deb12u3 || =2.10.34-1+deb12u4 || =2.10.34-1+deb12u5 || =2.10.34-1+deb12u6 || =2.10.34-1+deb12u7 || =2.10.34-1+deb12u8 || =2.10.34-1+deb12u9 || =2.10.36-1 || =2.10.36-2 || =2.10.36-3 || =2.10.38-1 || =2.10.38-2 || =2.99.10-1 || =2.99.12-1 || =2.99.12-2 || =2.99.14-1 || =2.99.14-2 || =2.99.16-1 || =2.99.16-2 || =2.99.18-1 || =3.0.0-1 || =3.0.0-2 || =3.0.0~rc1-1 || =3.0.0~rc1-3 || =3.0.0~rc1-4 || =3.0.0~rc2-1 || =3.0.0~rc3-1 || =3.0.2-1 || =3.0.2-2 || =3.0.2-3 || =3.0.2-3.1 || =3.0.4-1 || =3.0.4-2 || =3.0.4-3 || =3.0.4-4 || =3.0.4-5 || =3.0.4-6 || =3.0.4-6.1 || =3.0.4-6.2 || =3.0.6-1 || =3.2.0-1 || =3.2.0~rc2-1 || =3.2.0~rc2-2 || =3.2.0~rc2-3 || =3.2.0~rc2-3.1 || =3.2.0~rc2-3.2 || =3.2.0~rc2-3.3 || =3.2.0~rc3-1 || =3.2.2-1 || =3.2.4-1 || =3.2.4-2 || =3.2.4-3 || =3.2.6-1 | - |
 rpm rhel6 | | - | - |
 rpm rhel7 | | - | - |
 rpm rhel9 | | | 2:3.0.4-4.el9_8.14 |
 rpm rhel10 | | - | - |
 rpm rhel8 | | - | - |