Heap-based Buffer Overflow in GIMP PSP Plugin Allows Remote Code Execution

Heap-based Buffer Overflow in GIMP PSP Plugin Allows Remote Code Execution

CVE-2011-1782 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4543.

Learn more about our Web Application Penetration Testing UK.