Description: Marsu has discovered a vulnerability in Gimp, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an error within the "set_color_table()" function in plug-ins/common/sunras.c. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted .RAS file.
Successful exploitation may allow the execution of arbitrary code.
The vulnerability is confirmed in version 2.2.14. Other versions may also be affected.
Solution: Update to version 2.2.15.
Provided and/or discovered by: Marsu
Changelog: 2007-05-02: Added CVE reference.
2007-05-28: Updated "Solution" section.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.