rpm package
almalinux/gegl
pkg:rpm/almalinux/gegl
Vulnerabilities (29)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-2050 | Hig | 7.8 | < 0.2.0-40.el8_10 | 0.2.0-40.el8_10 | Jun 24, 2026 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a | |
| CVE-2019-20421 | Hig | 7.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Jan 27, 2020 | In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file. | |
| CVE-2019-13114 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Jun 30, 2019 | http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character. | |
| CVE-2019-13113 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Jun 30, 2019 | Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file. | |
| CVE-2019-13112 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Jun 30, 2019 | A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file. | |
| CVE-2019-13111 | Med | 5.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Jun 30, 2019 | A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file. | |
| CVE-2019-13109 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Jun 30, 2019 | An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction. | |
| CVE-2019-9143 | Hig | 8.8 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Feb 25, 2019 | An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. | |
| CVE-2018-20099 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Dec 12, 2018 | There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. | |
| CVE-2018-20098 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Dec 12, 2018 | There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. | |
| CVE-2018-20097 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Dec 12, 2018 | There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. | |
| CVE-2018-20096 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Dec 12, 2018 | There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. | |
| CVE-2018-19607 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Nov 27, 2018 | Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. | |
| CVE-2018-19535 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Nov 26, 2018 | In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file. | |
| CVE-2018-19108 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Nov 8, 2018 | In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file. | |
| CVE-2018-19107 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Nov 8, 2018 | In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file. | |
| CVE-2018-18915 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Nov 3, 2018 | There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack. | |
| CVE-2018-17581 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Sep 28, 2018 | CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service. | |
| CVE-2018-17282 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Sep 20, 2018 | An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference. | |
| CVE-2018-17230 | Med | 6.5 | < 0.2.0-39.el8 | 0.2.0-39.el8 | Sep 19, 2018 | Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file. |
- affected < 0.2.0-40.el8_10fixed 0.2.0-40.el8_10
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
- affected < 0.2.0-39.el8fixed 0.2.0-39.el8
Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
Page 1 of 2