CVE-2016-4994 PUBLISHED

Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.

EPSS 0.64% · 70.3th percentile

Risk Scores

EPSS Score
0.64%
70.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgimp0, 2.8.14-1ubuntu2, 2.8.14-1.2ubuntu1
Ubuntu:14.04:LTSgimp0, 2.8.10-0ubuntu1, 2.8.6-1ubuntu1

Timeline

References

Open in Interactive Console →