Login


 
Newsletter
Werbung
Sicherheit: Ausführen beliebiger Kommandos in GIMP
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in GIMP
ID: USN-1147-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Mo, 13. Juni 2011, 22:43
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1782

Originalnachricht


--===============2380730529578890436==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature"; boundary="=-MgqBsmpTgNagSvy2jPIO"


--=-MgqBsmpTgNagSvy2jPIO
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1147-1
June 13, 2011

gimp vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

GIMP could be made to run programs as your login if it opened a
specially crafted file.

Software Description:
- gimp: The GNU Image Manipulation Program

Details:

Nils Philippsen discovered that GIMP incorrectly handled malformed PSP
image files. If a user were tricked into opening a specially crafted PSP
image file, an attacker could cause GIMP to crash, or possibly execute
arbitrary code with the user's privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
gimp 2.6.11-1ubuntu6.1

Ubuntu 10.10:
gimp 2.6.10-1ubuntu3.3

Ubuntu 10.04 LTS:
gimp 2.6.8-2ubuntu1.3

After a standard system update you need to restart GIMP to make all the
necessary changes.

References:
CVE-2011-1782

Package Information:
https://launchpad.net/ubuntu/+source/gimp/2.6.11-1ubuntu6.1
https://launchpad.net/ubuntu/+source/gimp/2.6.10-1ubuntu3.3
https://launchpad.net/ubuntu/+source/gimp/2.6.8-2ubuntu1.3



--ÖgqBsmpTgNagSvy2jPIO
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJN9lIpAAoJEGVp2FWnRL6TcDEP/0soYnHEWR/38UUjrdX2/z/x
5BEpnGjOBhHJwiBdbSZOijqt9c/apv+Am7ZOXqMrhwQ9J4U7Hg+sZzGQo6ROcbay
HtVn+M0PTg7WjVF5hsSKJSNN60h3s5bXOPVa7/GvLfdkUpeohT9JMQgfbacdANhU
JVN2Xlo9q+9N5sNwQ4lOLyhDlW4yVpveXCbXt5YBZKBEOF7Xc+qQSoJQtvbGE0WR
sIosUOxn5TzUfLn2oOisSy/1b7cv+lR0pBaBZc4kRvXwfnouYmZq0wIn4JCqoz12
fnBLcBq2HVuwxFcOihP4Acc1fpQ65o0vKOkoZcS1s3Z4/bVtObTntvOGBLqmk8JU
O6qxbHCAwm7mdF0b2tq0JsJkhOYeQ7qqZaPN6AaDKcpdcXjRik+BlFo5BGf20Hpu
8zRbn1YkWcuXg1FFz9K7kC0ZTa/ne2qPXakiGRUIGzGF9jYH0RSyE+a2q05g8chY
gtQvnvwQJHm5Yb2G8UXScAxmKSL6Gffwn7aVUf3lyX6JdQtCvX+Xu5XxTNw8voyP
qD6xUZ7KQSIZGDEHgOnfz5PbZkPqL8j5t2JisSjETca8ATHQ9V4Isa902jQjDruI
h80QdHUfsab3fmNbc1KE0fOhh62JEdGJqKTpnf8Xz+0CYc5BxwgutPNRIjYLK7VA
ANkRsT0ulHeryZoT2jRC
=X4Wm
-----END PGP SIGNATURE-----

--=-MgqBsmpTgNagSvy2jPIO--



--===============2380730529578890436==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============2380730529578890436==--
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung