Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfh5-q868-q4pw

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the block_rem variable, occurs when a user opens a specially crafted .psd image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the block_rem variable, occurs when a user opens a specially crafted .psd image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

EPSS

Процентиль: 45%
0.00584
Низкий

8.4 High

CVSS3

Дефекты

CWE-191

Связанные уязвимости

CVSS3: 8.4
ubuntu
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

CVSS3: 8.4
redhat
2 месяца назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

CVSS3: 8.4
nvd
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

CVSS3: 8.4
debian
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, ...

EPSS

Процентиль: 45%
0.00584
Низкий

8.4 High

CVSS3

Дефекты

CWE-191