fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gimp | Gimp | * | 2.9.2 (excluding) |
Gimp | Ubuntu | devel | * |
Gimp | Ubuntu | hardy | * |
Gimp | Ubuntu | lucid | * |
Gimp | Ubuntu | natty | * |
Gimp | Ubuntu | oneiric | * |
Gimp | Ubuntu | precise | * |