CVE-2009-3909

EUVD-2009-3880
Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
gimpgimp
2.6.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gimp
bookworm
2.10.34-1+deb12u2
fixed
bookworm (security)
2.10.34-1+deb12u1
fixed
bullseye
2.10.22-4+deb11u2
fixed
bullseye (security)
2.10.22-4+deb11u1
fixed
sid
2.10.38-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gimp
dapper
ignored
hardy
not-affected
intrepid
Fixed 2.6.1-1ubuntu3.1
released
jaunty
Fixed 2.6.6-0ubuntu1.1
released
karmic
Fixed 2.6.7-1ubuntu1.1
released
References