CVE-2009-1570
RCETitle: Gimp RCE
RCE
Proof Of Concept
No public PoC currently indexed for CVE-2009-1570.
CWE Category
CWE-190
Published Date
Nov 13, 2009
Modified Date
Apr 09, 2025
Exploit Status
Not Found
Score
9.3
CVSS v2.0
Exploit Probability (EPSS)
3.08%
Vulnerability Summary
CVE-2009-1570: Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.
Impacted Vendors
Reference Links
http://git.gnome.org/cgit/gimp/commit/?h=gimp-2-6&id=df2b0aca2e7cdb95ebfd3454c65aaba0a83e9bbe
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html
http://secunia.com/advisories/37232
http://secunia.com/advisories/50737
http://secunia.com/secunia_research/2009-42/
http://security.gentoo.org/glsa/glsa-201209-23.xml
http://www.osvdb.org/59930
http://www.redhat.com/support/errata/RHSA-2011-0837.html
http://www.redhat.com/support/errata/RHSA-2011-0838.html
http://www.securityfocus.com/archive/1/507813/100/0/threaded
http://www.securityfocus.com/bid/37006
http://www.vupen.com/english/advisories/2009/3228
http://www.vupen.com/english/advisories/2009/3564
http://www.vupen.com/english/advisories/2010/1021
https://bugzilla.gnome.org/show_bug.cgi?id=600484
https://exchange.xforce.ibmcloud.com/vulnerabilities/54254
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8290
http://git.gnome.org/cgit/gimp/commit/?h=gimp-2-6&id=df2b0aca2e7cdb95ebfd3454c65aaba0a83e9bbe
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html
http://secunia.com/advisories/37232
http://secunia.com/advisories/50737
http://secunia.com/secunia_research/2009-42/
http://security.gentoo.org/glsa/glsa-201209-23.xml
http://www.osvdb.org/59930
http://www.redhat.com/support/errata/RHSA-2011-0837.html
http://www.redhat.com/support/errata/RHSA-2011-0838.html
http://www.securityfocus.com/archive/1/507813/100/0/threaded
http://www.securityfocus.com/bid/37006
http://www.vupen.com/english/advisories/2009/3228
http://www.vupen.com/english/advisories/2009/3564
http://www.vupen.com/english/advisories/2010/1021
https://bugzilla.gnome.org/show_bug.cgi?id=600484
https://exchange.xforce.ibmcloud.com/vulnerabilities/54254
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8290
CVSS v2.0
Source Entity
[email protected]
Severity
HIGH
9.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:C/I:C/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2009-1570 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:C/I:C/A:C
Affected Stack
No specific products linked.