Arbitrary code execution in GIMP in GNU Image Manipulation Program and Oracle Linux - CVE-2016-4994
Published: July 6, 2016 / Updated: January 11, 2017
Vulnerability identifier: #VU97
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4994
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allow a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a use-after-free memory error in the parsing of channel. A remote unauthenticated attacker can execute arbitrary code on the target user's system by sending a specially crafted XCF file to a vulnerable server.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
The vulnerability exists due to a use-after-free memory error in the parsing of channel. A remote unauthenticated attacker can execute arbitrary code on the target user's system by sending a specially crafted XCF file to a vulnerable server.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
GNU Image Manipulation Program
Oracle Linux
Arch Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Slackware Linux
Fedora
gimp (Alpine package)
gimp
Oracle Linux
Arch Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Slackware Linux
Fedora
gimp (Alpine package)
gimp
How to mitigate CVE-2016-4994
The vendor has issued a source code fix, available at:
https://git.gnome.org/browse/gimp/commit/?id=e82aaa4b4ee0703c879e35ea9321fff6be3e9b6f
https://git.gnome.org/browse/gimp/commit/?id=e82aaa4b4ee0703c879e35ea9321fff6be3e9b6f
gimp (Alpine package) - update to 2.8.18-r0
gimp - addressed in versions 2.8.16-2.fc22, 2.8.16-2.fc23, 2.8.16-2.fc24
gimp - addressed in versions 2.8.16-2.fc22, 2.8.16-2.fc23, 2.8.16-2.fc24