Title : GIMP PSD Plugin "seek_to_and_unpack_pixeldata()" Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-2421 CVE ID : CVE-2007-2949
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-03
Technical Description
A vulnerability has been identified in GIMP, which could be exploited by attackers to execute arbitrary code. This issue is caused by an integer overflow error in the "seek_to_and_unpack_pixeldata()" [plug-ins/common/psd.c] function when processing overly large width or height values read from a PSD file, which could be exploited by attackers to compromise an affected system by convincing a user to open a specially crafted file.