Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-79902

Опубликовано: 26 авг. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gimpunfixedpackage
gimpnot-affectedtrixiepackage
gimpnot-affectedbookwormpackage
gimpnot-affectedbullseyepackage

Примечания

  • https://gitlab.gnome.org/GNOME/gimp/-/work_items/16582

  • Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/fa9503bcc41e41ac0a5ae162a97486c79a7790ce

EPSS

Процентиль: 10%
0.00201
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
22 дня назад

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

CVSS3: 5.5
redhat
около 2 месяцев назад

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

CVSS3: 5.5
nvd
22 дня назад

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

CVSS3: 5.5
github
22 дня назад

A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin allocates a Variable-Length Array (VLA) on the stack without integer overflow checks, causing an unbounded stack allocation. This issue leads to an application crash, resulting in a denial of service.

EPSS

Процентиль: 10%
0.00201
Низкий