Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40917

Опубликовано: 15 апр. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gimpfixed3.2.2-1package
gimpfixed3.0.4-3+deb13u8trixiepackage
gimpnot-affectedbookwormpackage
gimpnot-affectedbullseyepackage

Примечания

  • https://gitlab.gnome.org/GNOME/gimp/-/issues/16056

  • Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/3264a671125809cefb4e4d3cf9c07c0c81edcbf2 (GIMP_3_2_2)

EPSS

Процентиль: 6%
0.00167
Низкий

Связанные уязвимости

CVSS3: 5
ubuntu
4 месяца назад

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

CVSS3: 5
redhat
4 месяца назад

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

CVSS3: 5
nvd
4 месяца назад

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

suse-cvrf
около 1 месяца назад

Security update for gimp

CVSS3: 5
github
4 месяца назад

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that process such files.

EPSS

Процентиль: 6%
0.00167
Низкий