

- GIMP 2.8.22 NORMAL MAP PLUGIN PATCH
- GIMP 2.8.22 NORMAL MAP PLUGIN PRO
- GIMP 2.8.22 NORMAL MAP PLUGIN CODE
GIMP 2.8.22 NORMAL MAP PLUGIN CODE
Successful exploitation of this issue could result in remote code execution in a virtual machine via the authenticated VNC session. VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a stack overflow via a specific set of VNC packets. In addition, ESXi must be configured to allow VNC traffic through the built-in firewall. Note: In order for exploitation to be possible in ESXi, VNC must be manually enabled in a virtual machine’s. VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vulnerability that could allow an authenticated VNC session to cause a heap overflow via a specific set of VNC packets resulting in heap corruption. This could potentially result in code execution, arbitrary file writes, or other attacks.

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This issue may allow a guest to execute code on the host.
GIMP 2.8.22 NORMAL MAP PLUGIN PATCH
VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. The issue is reduced to a Denial of Service of the guest on ESXi 5.5.

GIMP 2.8.22 NORMAL MAP PLUGIN PRO
The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG Workstation Pro / Player 12.x prior to 12.5.5 and Fusion Pro / Fusion 8.x prior to 8.5.6 has uninitialized memory usage. VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG Workstation Pro / Player 12.x prior to 12.5.5 and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA.
