Vulnerability Report

CVE-2007-2949

RCE

Title: Gimp RCE

RCE

Proof Of Concept

No public PoC currently indexed for CVE-2007-2949.

CWE Category CWE-190
Published Date Jul 04, 2007
Modified Date Apr 09, 2025
Exploit Status Not Found
Score 6.8 CVSS v2.0
Exploit Probability (EPSS)
34.77%

Vulnerability Summary

CVE-2007-2949: Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.

Impacted Vendors

Reference Links

http://issues.foresightlinux.org/browse/FL-457 http://osvdb.org/37804 http://secunia.com/advisories/25677 http://secunia.com/advisories/25949 http://secunia.com/advisories/26044 http://secunia.com/advisories/26132 http://secunia.com/advisories/26215 http://secunia.com/advisories/26384 http://secunia.com/advisories/26575 http://secunia.com/advisories/26939 http://secunia.com/advisories/28114 http://secunia.com/secunia_research/2007-63/advisory/ http://security.gentoo.org/glsa/glsa-200707-09.xml http://sunsolve.sun.com/search/document.do?assetkey=1-26-103170-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-201320-1 http://svn.gnome.org/viewcvs/gimp?view=revision&revision=22798 http://www.debian.org/security/2007/dsa-1335 http://www.kb.cert.org/vuls/id/399896 http://www.mandriva.com/security/advisories?name=MDKSA-2007:170 http://www.novell.com/linux/security/advisories/2007_15_sr.html http://www.redhat.com/support/errata/RHSA-2007-0513.html http://www.securityfocus.com/bid/24745 http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.360191 http://www.ubuntu.com/usn/usn-480-1 http://www.vupen.com/english/advisories/2007/2421 http://www.vupen.com/english/advisories/2007/4241 https://exchange.xforce.ibmcloud.com/vulnerabilities/35246 https://issues.rpath.com/browse/RPL-1487 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11276 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5772 http://issues.foresightlinux.org/browse/FL-457 http://osvdb.org/37804 http://secunia.com/advisories/25677 http://secunia.com/advisories/25949 http://secunia.com/advisories/26044 http://secunia.com/advisories/26132 http://secunia.com/advisories/26215 http://secunia.com/advisories/26384 http://secunia.com/advisories/26575 http://secunia.com/advisories/26939 http://secunia.com/advisories/28114 http://secunia.com/secunia_research/2007-63/advisory/ http://security.gentoo.org/glsa/glsa-200707-09.xml http://sunsolve.sun.com/search/document.do?assetkey=1-26-103170-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-201320-1 http://svn.gnome.org/viewcvs/gimp?view=revision&revision=22798 http://www.debian.org/security/2007/dsa-1335 http://www.kb.cert.org/vuls/id/399896 http://www.mandriva.com/security/advisories?name=MDKSA-2007:170 http://www.novell.com/linux/security/advisories/2007_15_sr.html http://www.redhat.com/support/errata/RHSA-2007-0513.html http://www.securityfocus.com/bid/24745 http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.360191 http://www.ubuntu.com/usn/usn-480-1 http://www.vupen.com/english/advisories/2007/2421 http://www.vupen.com/english/advisories/2007/4241 https://exchange.xforce.ibmcloud.com/vulnerabilities/35246 https://issues.rpath.com/browse/RPL-1487 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11276 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5772
CVSS v2.0
Source Entity [email protected]
Severity MEDIUM
6.8
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:M/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2007-2949 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.