Vulnerability Name:

CVE-2017-17789 (CCN-136548)

Assigned:2017-12-20
Published:2017-12-20
Updated:2022-02-07
Summary:In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-17789

Source: CCN
Type: oss-security Mailing List, Tue, 19 Dec 2017 17:11:19 +0100
GIMP parser bugs (FLIMP and more)

Source: MISC
Type: Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2017/12/19/5

Source: BID
Type: Third Party Advisory, VDB Entry
102898

Source: CCN
Type: BID-102898
GIMP CVE-2017-17789 Heap Buffer Overflow Vulnerability

Source: CCN
Type: GNOME Bug 790849
(CVE-2017-17789) CVE-2017-17789 Heap buffer overflow in PSP importer, function

Source: MISC
Type: Exploit, Issue Tracking, Patch, Third Party Advisory
https://bugzilla.gnome.org/show_bug.cgi?id=790849

Source: XF
Type: UNKNOWN
gimp-cve201717789-bo(136548)

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20171223 [SECURITY] [DLA 1220-1] gimp security update

Source: UBUNTU
Type: Third Party Advisory
USN-3539-1

Source: DEBIAN
Type: Third Party Advisory
DSA-4077

Source: CCN
Type: GIMP Web site
GIMP

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2017-17789

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gimp:gimp:2.8.22:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201717789
    V
    CVE-2017-17789
    2022-09-01
    oval:org.opensuse.security:def:3772
    P
    Security update for postgresql-jdbc (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:3760
    P
    Security update for 389-ds (Important)
    2022-07-06
    oval:org.opensuse.security:def:3035
    P
    coolkey-1.1.0-148.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3073
    P
    g3utils-1.1.36-58.6.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3041
    P
    cron-4.2-59.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3082
    P
    glibc-2.22-100.15.4 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3120
    P
    krb5-1.12.5-40.37.7 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3053
    P
    dnsmasq-2.78-18.9.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3106
    P
    ibus-chewing-1.4.14-4.11 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3031
    P
    chrony-2.3-5.6.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3122
    P
    lcms2-2.7-9.7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3067
    P
    file-5.22-10.12.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3112
    P
    java-1_7_0-openjdk-1.7.0.231-43.27.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:4729
    P
    Security update for the Linux Kernel (Important)
    2021-11-17
    oval:org.opensuse.security:def:51686
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:65672
    P
    Security update for go1.17 (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:47684
    P
    libXt6-1.1.4-3.57 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47653
    P
    java-1_8_0-openjdk-1.8.0.181-27.26.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47589
    P
    cyrus-sasl-2.1.26-8.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47443
    P
    mailx-12.5-28.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47755
    P
    libopenssl1_1-1.1.1-1.9 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46991
    P
    libXext6-1.3.2-3.60 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47527
    P
    wpa_supplicant-2.2-14.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47082
    P
    libsystemd0-228-117.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47229
    P
    cron-4.2-58.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:63332
    P
    gtk-vnc-devel-1.0.0-2.35 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63470
    P
    finch-2.13.0-10.105 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63130
    P
    python3-keystoneclient-4.0.0-9.4.5 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:65582
    P
    Security update for jdom2 (Important)
    2021-07-12
    oval:org.opensuse.security:def:4749
    P
    Security update for cryptctl (Important)
    2021-06-23
    oval:org.opensuse.security:def:51580
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:48447
    P
    iputils-s20121221-2.17 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48393
    P
    cups-1.7.5-12.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46859
    P
    tomcat-8.0.23-1.80 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46533
    P
    logwatch-7.4.0-13.101 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46534
    P
    mailman-2.1.17-1.18 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62851
    P
    cvs-1.12.12-2.30 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46547
    P
    pam_ssh-2.0-1.39 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46667
    P
    gnome-settings-daemon-3.10.2-20.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69654
    P
    Security update for nginx (Important)
    2021-06-02
    oval:org.opensuse.security:def:5699
    P
    Security update for rubygem-actionpack-5_1 (Important)
    2021-05-26
    oval:org.opensuse.security:def:5030
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:5668
    P
    Security update for webkit2gtk3 (Important)
    2021-04-29
    oval:org.opensuse.security:def:4721
    P
    Security update for the Linux Kernel (Important)
    2021-04-13
    oval:org.opensuse.security:def:51172
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:69549
    P
    Security update for python-urllib3 (Moderate)
    2021-02-08
    oval:org.opensuse.security:def:64519
    P
    Security update for wavpack (Moderate)
    2021-01-21
    oval:org.opensuse.security:def:5017
    P
    Security update for php72 (Moderate)
    2021-01-14
    oval:org.opensuse.security:def:4971
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:62651
    P
    libSDL-1_2-0-1.2.15-3.9.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62674
    P
    libimobiledevice-devel-1.2.0+git20180427.26373b3-1.40 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72372
    P
    libSoundTouch0-1.8.0-3.11.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72256
    P
    libSoundTouch0-1.8.0-3.11.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62650
    P
    libQt5OpenGLExtensions-devel-static-5.12.7-2.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4839
    P
    Security update for subversion (Important)
    2020-12-02
    oval:org.opensuse.security:def:4854
    P
    Security update for qemu (Important)
    2020-12-02
    oval:org.opensuse.security:def:51852
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4873
    P
    Security update for freetds (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:5010
    P
    Security update for tomcat (Important)
    2020-12-02
    oval:org.opensuse.security:def:5003
    P
    Security update for php7 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4794
    P
    Security update for nginx (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4946
    P
    Security update for virt-bootstrap (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:51012
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52243
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:19326
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64157
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:18331
    P
    Security update for libjpeg-turbo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18565
    P
    Security update for spice-gtk (Important)
    2020-12-01
    oval:org.opensuse.security:def:24912
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25258
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:74585
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:74459
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:18204
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18688
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:66318
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:49694
    P
    libsoup-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50300
    P
    Security update for zsh (Important)
    2020-12-01
    oval:org.opensuse.security:def:18666
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:26279
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:51034
    P
    Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork (Important)
    2020-12-01
    oval:org.opensuse.security:def:18654
    P
    Security update for dpdk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66226
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:64263
    P
    glibc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26244
    P
    Security update for openconnect (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18388
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:18597
    P
    Security update for texlive (Important)
    2020-12-01
    oval:org.opensuse.security:def:25038
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25408
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:50794
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:52205
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:50763
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:50698
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:52143
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:24839
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:49899
    P
    apache2-mod_wsgi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50538
    P
    Security update for python-Flask (Low)
    2020-12-01
    oval:org.opensuse.security:def:25606
    P
    Security update for libjpeg-turbo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:69019
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:25562
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:63696
    P
    Security update for libtasn1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25548
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:68916
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18212
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:18419
    P
    Security update for mercurial (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49548
    P
    libgme-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25119
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25461
    P
    Security update for cpio (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50867
    P
    Security update for postgresql12 (Important)
    2020-12-01
    oval:org.opensuse.security:def:52442
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53873
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:52406
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:73007
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:52334
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:53799
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49549
    P
    libgxps-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50045
    P
    apache2-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50628
    P
    Security update for expat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:72889
    P
    Security update for php7 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51409
    P
    Security update for zypper, libzypp and libsolv (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52135
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:64023
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:18246
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:18455
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:24849
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25175
    P
    Security update for libssh (Important)
    2020-12-01
    oval:org.opensuse.security:def:51011
    P
    Security update for java-11-openjdk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52523
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64407
    P
    libxml2-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:19352
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:49567
    P
    libopenjpeg1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50143
    P
    enigmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64365
    P
    libpcre1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:93394
    P
    (Moderate)
    2020-11-23
    oval:org.opensuse.security:def:110209
    P
    Security update for gimp (Low)
    2020-09-13
    oval:org.opensuse.security:def:104693
    P
    Security update for gimp (Low)
    2020-09-10
    oval:org.opensuse.security:def:98003
    P
    Security update for gimp (Low)
    2020-09-10
    oval:org.opensuse.security:def:75399
    P
    Security update for gimp (Low)
    2020-09-10
    oval:org.opensuse.security:def:99885
    P
    Security update for gimp (Low)
    2020-09-10
    oval:org.opensuse.security:def:91038
    P
    Security update for gimp (Low)
    2020-09-10
    oval:com.ubuntu.xenial:def:2017177890000000
    V
    CVE-2017-17789 on Ubuntu 16.04 LTS (xenial) - low.
    2017-12-20
    oval:com.ubuntu.artful:def:201717789000
    V
    CVE-2017-17789 on Ubuntu 17.10 (artful) - low.
    2017-12-20
    oval:com.ubuntu.xenial:def:201717789000
    V
    CVE-2017-17789 on Ubuntu 16.04 LTS (xenial) - low.
    2017-12-20
    oval:com.ubuntu.disco:def:2017177890000000
    V
    CVE-2017-17789 on Ubuntu 19.04 (disco) - low.
    2017-12-20
    oval:com.ubuntu.bionic:def:201717789000
    V
    CVE-2017-17789 on Ubuntu 18.04 LTS (bionic) - low.
    2017-12-20
    oval:com.ubuntu.cosmic:def:2017177890000000
    V
    CVE-2017-17789 on Ubuntu 18.10 (cosmic) - low.
    2017-12-20
    oval:com.ubuntu.cosmic:def:201717789000
    V
    CVE-2017-17789 on Ubuntu 18.10 (cosmic) - low.
    2017-12-20
    oval:com.ubuntu.bionic:def:2017177890000000
    V
    CVE-2017-17789 on Ubuntu 18.04 LTS (bionic) - low.
    2017-12-20
    oval:com.ubuntu.trusty:def:201717789000
    V
    CVE-2017-17789 on Ubuntu 14.04 LTS (trusty) - low.
    2017-12-20
    BACK
    gimp gimp 2.8.22
    debian debian linux 9.0
    debian debian linux 7.0
    debian debian linux 8.0
    canonical ubuntu linux 14.04