CVE-2006-4519
Last modified
CVE-2006-4519 is a vulnerability of currently unknown severity. Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.. EPSS estimates a 5.60% chance of exploitation in the next 30 days.
Description
Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gimp | Gimp | < 2.2.16 |
References
- http://bugzilla.gnome.org/show_bug.cgi?id=451379Issue Tracking, Third Party Advisory
- http://developer.gimp.org/NEWS-2.2Broken Link
- http://osvdb.org/42139Broken Link
- http://osvdb.org/42140Broken Link
- http://osvdb.org/42141Broken Link
- http://osvdb.org/42142Broken Link
- http://osvdb.org/42143Broken Link
- http://osvdb.org/42144Broken Link
- http://osvdb.org/42145Broken Link
- http://secunia.com/advisories/26132Broken Link
- http://secunia.com/advisories/26215Broken Link
- http://secunia.com/advisories/26240Broken Link
- http://secunia.com/advisories/26575Broken Link
- http://secunia.com/advisories/26939Broken Link
- http://security.gentoo.org/glsa/glsa-200707-09.xmlThird Party Advisory
- http://www.debian.org/security/2007/dsa-1335Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0513.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/475257/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/24835Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018349Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-494-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35308Third Party Advisory, VDB Entry
- http://bugzilla.gnome.org/show_bug.cgi?id=451379Issue Tracking, Third Party Advisory
- http://developer.gimp.org/NEWS-2.2Broken Link
- http://osvdb.org/42139Broken Link
- http://osvdb.org/42140Broken Link
- http://osvdb.org/42141Broken Link
- http://osvdb.org/42142Broken Link
- http://osvdb.org/42143Broken Link
- http://osvdb.org/42144Broken Link
- http://osvdb.org/42145Broken Link
- http://secunia.com/advisories/26132Broken Link
- http://secunia.com/advisories/26215Broken Link
- http://secunia.com/advisories/26240Broken Link
- http://secunia.com/advisories/26575Broken Link
- http://secunia.com/advisories/26939Broken Link
- http://security.gentoo.org/glsa/glsa-200707-09.xmlThird Party Advisory
- http://www.debian.org/security/2007/dsa-1335Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0513.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/475257/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/24835Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018349Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-494-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35308Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4519?
How severe is CVE-2006-4519?
How do I fix CVE-2006-4519?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-4511Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.…
- CVE-2006-4513Multiple integer overflows in the WV library in wvWare (form…
- CVE-2006-4514Heap-based buffer overflow in the ole_info_read_metabat func…
- CVE-2006-4516Integer signedness error in FreeBSD 6.0-RELEASE allows local…
- CVE-2006-4517Novell iManager 2.5 and 2.0.2 allows remote attackers to cau…
- CVE-2006-4518Qbik WinGate 6.1.4 and earlier allows remote attackers to ca…
- CVE-2006-4520ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before …
- CVE-2006-4521The BerDecodeLoginDataRequest function in the libnmasldap.so…
- CVE-2006-4522Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 a…
- CVE-2006-4523The web-based management interface in 2Wire, Inc. HomePortal…
- CVE-2006-4524Multiple SQL injection vulnerabilities in login_verif.asp in…
- CVE-2006-4525Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 …
Are you affected by CVE-2006-4519?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
