Back to Database
Status published
Medium
CVE-2007-3126
Gimp before 2.8.22 allows context-dependent attackers to cause a denial...
Vulnerability Description
Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3126
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/43453
- https://bugzilla.gnome.org/show_bug.cgi?id=778604
- https://git.gnome.org/browse/gimp/commit/?id=323ecb73f7bf36788fb7066eb2d6678830cd5de7
- http://www.securityfocus.com/archive/1/470751/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34789
- https://www.gimp.org/news/2017/05/11/gimp-2-8-22-released/
More from gimp
View All →CVE-2022-32990
An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers...
Medium
5.5
CVE-2022-30067
GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through...
Medium
5.5
CVE-2018-12713
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames,...
Critical
9.1
CVE-2017-17789
In GIMP 2.8.22, there is a heap-based buffer overflow in...
High
7.8
CVE-2017-17788
In GIMP 2.8.22, there is a stack-based buffer over-read in...
Medium
5.5
Affected Vendor
gimp
View all reports →Affected Software
gimp
Vulnerable Versions:
0
Timeline
Official Publish:
June 8th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.