CVE-2012-3403
EPSS 4.3%
Description
Heap-based buffer overflow in the KiSS CEL file format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted KiSS palette file, which triggers an "invalid free."
How to fix CVE-2012-3403
To remediate CVE-2012-3403, upgrade the affected package to a fixed version below.
- Debian/gimp—upgrade to 2.8.2-1 or later
Is CVE-2012-3403 being exploited?
Low — EPSS is 4.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.8.2-1