// For flags

CVE-2010-4540

Gimp: Stack-based buffer overflow in Lighting plug-in

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in the load_preset_response function in plug-ins/lighting/lighting-ui.c in the "LIGHTING EFFECTS > LIGHT" plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long Position field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself. NOTE: some of these details are obtained from third party information.

Hay un desbordamiento del búfer en la región stack de la memoria en la función load_preset_response en el archivo plug-ins/lighting/lighting-ui.c en el plugin "LIGHTING EFFECTS> LIGHT" en GIMP versión 2.6.11 permite a los atacantes remotos asistidos por el usuario generar una denegación de servicio (bloqueo de la aplicación ) o posiblemente ejecute código arbitrario por medio de un largo campo de posición en una configuración de archivo del plugin. NOTA: puede ser poco común obtener un archivo de configuración de plugin GIMP de una fuente no confiable que sea independiente de la distribución del plugin en sí. NOTA: algunos de estos detalles se obtienen a partir de información de terceros.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-12-09 CVE Reserved
  • 2011-01-07 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-121: Stack-based Buffer Overflow
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gimp
Search vendor "Gimp"
Gimp
Search vendor "Gimp" for product "Gimp"
2.6.11
Search vendor "Gimp" for product "Gimp" and version "2.6.11"
-
Affected