Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-48796

Опубликовано: 27 мая 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gimpfixed3.0.0~RC1-4package
gimpnot-affectedbookwormpackage
gimpnot-affectedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2368559

  • https://gitlab.gnome.org/GNOME/gimp/-/issues/9257

  • https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/879

  • Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0dc98936a0d9f5a70025f4e9cf321d1118ea500e (GIMP_2_99_16)

  • Introduced in: https://gitlab.gnome.org/GNOME/gimp/-/commit/aa51b9e19ece8a8c54a513fe33b6d65abcb0fbfb (GIMP_2_99_12)

EPSS

Процентиль: 2%
0.00014
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
23 дня назад

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

CVSS3: 7.3
redhat
24 дня назад

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

CVSS3: 7.3
nvd
23 дня назад

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

CVSS3: 7.3
github
23 дня назад

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

EPSS

Процентиль: 2%
0.00014
Низкий