Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59087

Опубликовано: 10 авг. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gimpunfixedpackage
gimpnot-affectedtrixiepackage
gimpnot-affectedbookwormpackage
gimpnot-affectedbullseyepackage

Примечания

  • https://gitlab.gnome.org/GNOME/gimp/-/work_items/16491

  • Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bb36034bedb06305402ce836129efe8c8d4ad41d

EPSS

Процентиль: 39%
0.00478
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
17 дней назад

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
redhat
2 месяца назад

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
nvd
17 дней назад

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
github
17 дней назад

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
fstec
2 месяца назад

Уязвимость загрузчика файлов Seattle Filmworks библиотеки для обработки изображений Gimp, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

EPSS

Процентиль: 39%
0.00478
Низкий