Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
Updated: 06/01/2019
Detect date
?
07/12/2016
Severity
?
High
Description
Use-after-free vulnerability was found in GIMP. By exploiting this vulnerability malicious users can cause denial of service or execute arbitrary code. This vulnerability can be exploited remotely via a specially designed XCF file.
Technical details
This vulnerability related to xcf_load_image function in app/xcf/xcf-load.c .
Affected products
GIMP versions earlier than 2.8.18
Solution
Update to the latest version
GIMP downloads page
Original advisories
GIMP update new
Impacts
?
ACE
[?]
DoS
[?]
CVE-IDS
?
CVE-2016-49946.8High"
I got this result from a AV scan
Is it something we should be concerned about does anyone know? I don't wan't DOS attacks on my machine
And If so why aren't PC Mark updating the Gimp version?
i have actually alot of fonts, downloaded from a free homepage... does it affect the test? latest version of W10
Updating Gimp would affect scores. We generally do not do that.
This vulnerability is very theoretical with PCMark 10 as you do not use the version inside PCMark 10 except to run specific PCMark 10 tests (which have fixed files which they load). Only way this would apply is if you went to manually start the Gimp from inside PCMark 10 install folders and then used that to open a boobytrapped file. So as long as you do not do that and only PCMark 10 itself starts its Gimp, this issue cannot occur.
Does the same thing occur if you install normal standalone version of GIMP on your system and try to start it?
If it does, it suggests you may have corrupted font present in your system.
I have around 1200 fonts in my system, and the initial loading took about 10 mins. When I check the task manager, there's one thread at full loads and I can see read activities on OS drive.