|
Message-ID: <887697103.140954.1294149892279.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com> Date: Tue, 4 Jan 2011 09:04:52 -0500 (EST) From: Josh Bressers <bressers@...hat.com> To: oss-security@...ts.openwall.com Cc: "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: CVE request for buffer overflows in gimp ----- Original Message ----- > Hello Steve, Vendors, > > This one is from the debian bug tracker [1], there are four buffer > overflows in gimp plugins. > > I am not sure if this would need one CVE or four? > > [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608497 > > I'm going to give this four. We *might* be able to get away with two, but since they're all in quite different bits of code, I'm betting the affected versions are different, and it's likely upstream is going to fix these all at different times in their SCM. CVE-2010-4540 gimp LIGHTING EFFECTS > LIGHT plugin stack buffer overflow CVE-2010-4541 gimp SPHERE DESIGNER plugin stack buffer overflow CVE-2010-4542 gimp GFIG plugin stack buffer overflow CVE-2010-4543 gimp heap overflow read_channel_data() in file-psp.c Thanks. -- JB
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.