Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf24-j29f-vrgj

Опубликовано: 28 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

EPSS

Процентиль: 8%
0.00186
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.1
ubuntu
19 дней назад

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

CVSS3: 6.1
redhat
около 2 месяцев назад

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

CVSS3: 6.1
nvd
19 дней назад

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents.

CVSS3: 6.1
debian
19 дней назад

A flaw was found in the file-pvr plugin in GIMP. When processing a spe ...

EPSS

Процентиль: 8%
0.00186
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-125