Unrated severityNVD Advisory· Published Jul 12, 2012· Updated Apr 29, 2026
CVE-2012-3236
CVE-2012-3236
Description
fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- archives.neohapsis.com/archives/bugtraq/2012-06/0192.htmlnvdBroken LinkExploit
- git.gnome.org/browse/gimp/commit/plug-ins/file-fits/fits-io.cnvdExploitPatchVendor Advisory
- www.exploit-db.com/exploits/19482nvdExploitThird Party AdvisoryVDB Entry
- www.reactionpenetrationtesting.co.uk/FIT-file-handling-dos.htmlnvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2012-09/msg00000.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/54246nvdBroken LinkThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-1559-1nvdThird Party Advisory
- bugzilla.gnome.org/show_bug.cginvdIssue TrackingThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/76658nvdThird Party AdvisoryVDB Entry
- www.mandriva.com/security/advisoriesnvdBroken Link
News mentions
0No linked articles in our index yet.