CVE-2012-3402
plug-in): Heap-buffer overflow by decoding certain PSD headers
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in plug-ins/common/psd.c in the Adobe Photoshop PSD plugin in GIMP 2.2.13 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted channels header value in a PSD image file, which triggers a heap-based buffer overflow, a different vulnerability than CVE-2009-3909.
Desbordamiento de entero en plug-ins/common/psd.c en el plugin de Adobe Photoshop PSD en GIMP 2.2.13 y anteriores permite a atacantes remotos provocar una denegación de servicio y posiblemente ejecutar código arbitrario a través de un valor de encabezado canales diseñado en un archivo de imagen PSD, lo que provoca un desbordamiento de búfer basado en heap, una vulnerabilidad diferente a CVE-2009-3909.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-06-14 CVE Reserved
- 2012-08-20 CVE Published
- 2024-03-25 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/50737 | Broken Link | |
http://www.openwall.com/lists/oss-security/2012/08/20/6 | Mailing List | |
http://www.securitytracker.com/id?1027411 | Broken Link | |
https://bugzilla.redhat.com/attachment.cgi?id=603059&action=diff | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2012-1181.html | 2023-02-13 | |
http://security.gentoo.org/glsa/glsa-201209-23.xml | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=838941 | 2012-08-20 | |
https://access.redhat.com/security/cve/CVE-2012-3402 | 2012-08-20 |