Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqxg-r7gf-m7m7

Опубликовано: 24 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

EPSS

Процентиль: 8%
0.00184
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.1
ubuntu
24 дня назад

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

CVSS3: 6.1
redhat
около 2 месяцев назад

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

CVSS3: 6.1
nvd
24 дня назад

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents into an intermediate file.

CVSS3: 6.1
debian
24 дня назад

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing ...

EPSS

Процентиль: 8%
0.00184
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125