Arbitrary code execution in GIMP in GNU Image Manipulation Program and Oracle Linux - CVE-2016-4994

 

Arbitrary code execution in GIMP in GNU Image Manipulation Program and Oracle Linux - CVE-2016-4994

Published: July 6, 2016 / Updated: January 11, 2017


Vulnerability identifier: #VU97
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4994
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allow a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a use-after-free memory error in the parsing of channel. A remote unauthenticated attacker can execute arbitrary code on the target user's system by sending a specially crafted XCF file to a vulnerable server.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Affected software

GNU Image Manipulation Program
Oracle Linux
Arch Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Slackware Linux
Fedora
gimp (Alpine package)
gimp

How to mitigate CVE-2016-4994

The vendor has issued a source code fix, available at:

https://git.gnome.org/browse/gimp/commit/?id=e82aaa4b4ee0703c879e35ea9321fff6be3e9b6f

gimp (Alpine package) - update to 2.8.18-r0
gimp - addressed in versions 2.8.16-2.fc22, 2.8.16-2.fc23, 2.8.16-2.fc24

External References

Related Security Bulletins