Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6694

Опубликовано: 03 авг. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gimpfixed3.2.4-1package

Примечания

  • https://gitlab.gnome.org/GNOME/gimp/-/work_items/16150

  • Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bfec7079f0196fa1b3156e574f6778537cb4a5b6 (GIMP_3_2_4)

EPSS

Процентиль: 5%
0.00149
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 дня назад

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.

CVSS3: 5.5
redhat
4 месяца назад

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.

CVSS3: 5.5
nvd
4 дня назад

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.

CVSS3: 5.5
github
4 дня назад

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.

EPSS

Процентиль: 5%
0.00149
Низкий