In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no ‘\0’ character after the version string.
CVE-2017-17788 (debian_linux, gimp, ubuntu_linux)
Leave a reply
410-897-9494
Receive RedZone Security Updates in Your InboxContact Us
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no ‘\0’ character after the version string.
You must be logged in to post a comment.