{"id":"UBUNTU-CVE-2012-4433","details":"Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.","modified":"2025-07-16T08:10:36.907048Z","published":"2012-11-18T23:55:00Z","withdrawn":"2025-07-18T16:42:47Z","upstream":["CVE-2012-4433"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2012-4433"},{"type":"REPORT","url":"http://seclists.org/oss-sec/2012/q4/215"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2012-4433"}],"affected":[{"package":{"name":"gegl","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/gegl@0.2.0-4ubuntu1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.0-4ubuntu1"}]}],"versions":["0.2.0-3ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"gegl","binary_version":"0.2.0-4ubuntu1"},{"binary_name":"libgegl-0.2-0","binary_version":"0.2.0-4ubuntu1"},{"binary_name":"libgegl-0.2-0-dbg","binary_version":"0.2.0-4ubuntu1"},{"binary_name":"libgegl-dev","binary_version":"0.2.0-4ubuntu1"},{"binary_name":"libgegl-doc","binary_version":"0.2.0-4ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-4433.json"}},{"package":{"name":"gegl","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/gegl@0.3.4-1ubuntu2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.4-1ubuntu2"}]}],"versions":["0.3.0-4ubuntu2","0.3.2-1ubuntu1","0.3.2-1ubuntu2","0.3.4-1ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"gegl","binary_version":"0.3.4-1ubuntu2"},{"binary_name":"gegl-dbgsym","binary_version":"0.3.4-1ubuntu2"},{"binary_name":"libgegl-0.3-0","binary_version":"0.3.4-1ubuntu2"},{"binary_name":"libgegl-0.3-0-dbg","binary_version":"0.3.4-1ubuntu2"},{"binary_name":"libgegl-0.3-0-dbgsym","binary_version":"0.3.4-1ubuntu2"},{"binary_version":"0.3.4-1ubuntu2","binary_name":"libgegl-dev"},{"binary_name":"libgegl-dev-dbgsym","binary_version":"0.3.4-1ubuntu2"},{"binary_name":"libgegl-doc","binary_version":"0.3.4-1ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-4433.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"low"}]}