Logo
vulnerabilityCVE-2022-32990
Name
CVE-2022-32990
Source
NVD ( link)Debian ( link)
Description
An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
gimp
Patched

Vulnerability Ratings#


5.5
CVSSv31
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
3.2.4
Not Affected
yocto
scarthgap
2.10.38
Not Affected

Resolved with patches#


gimp (yocto:kirkstone)

#
Title
Author
Resolve
1
app: check for invalid offsets when loading XCF files
Jacob Boerema <jgboerema@gmail.com>
CVE-2022-32990
2
app: check max dimensions when loading xcf files
Jacob Boerema <jgboerema@gmail.com>
CVE-2022-32990
3
app: fix #8230 crash in gimp_layer_invalidate_boundary when
Jacob Boerema <jgboerema@gmail.com>
CVE-2022-32990