Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Mandriva Security Update Fixes Gimp XCF File Handling Buffer Overflow Vulnerability

Title : Mandriva Security Update Fixes Gimp XCF File Handling Buffer Overflow Vulnerability
VUPEN ID : VUPEN/ADV-2006-2890
CVE ID : CVE-2006-3404
Rated as : Moderate Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-07-19


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

Mandriva has released updated packages to address a vulnerability identified in Gimp. This flaw could be exploited by attackers to execute arbitrary commands. For additional information, see : VUPEN/ADV-2006-2703

Affected Products

Mandriva Linux 2006.0

Solution

Upgrade the affected packages :

Mandriva Linux 2006.0:
ef770a8f1e5b894589b8f591486e00b9 2006.0/RPMS/gimp-2.2.8-6.1.20060mdk.i586.rpm
f39e2f6d7bd2e88e47b696b58aa8023b 2006.0/RPMS/gimp-python-2.2.8-6.1.20060mdk.i586.rpm
465e5b21384bc501d2e991922695811f 2006.0/RPMS/libgimp2.0_0-2.2.8-6.1.20060mdk.i586.rpm
1df661eb0a251358f5bc7c6e35929b71 2006.0/RPMS/libgimp2.0-devel-2.2.8-6.1.20060mdk.i586.rpm
708dd714d5514cfb89a947bca6604b73 2006.0/SRPMS/gimp-2.2.8-6.1.20060mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
20fe9e1f09f22f770c608303edfad886 x86_64/2006.0/RPMS/gimp-2.2.8-6.1.20060mdk.x86_64.rpm
a61b7e401cf01bb3715702d557b0fca6 x86_64/2006.0/RPMS/gimp-python-2.2.8-6.1.20060mdk.x86_64.rpm
e1d614c2befbec26c478eb1303ad887e x86_64/2006.0/RPMS/lib64gimp2.0_0-2.2.8-6.1.20060mdk.x86_64.rpm
8b7168186005e221d8aa58d37349d36d x86_64/2006.0/RPMS/lib64gimp2.0-devel-2.2.8-6.1.20060mdk.x86_64.rpm
708dd714d5514cfb89a947bca6604b73 x86_64/2006.0/SRPMS/gimp-2.2.8-6.1.20060mdk.src.rpm

References

http://www.vupen.com/english/advisories/2006/2890
http://www.frsirt.com/english/reference/16263

ChangeLog

2006-07-19 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-07-06

     

  Microsoft Windows 0-Day
  Flaw Exploited in the Wild


  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy