Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59090

Опубликовано: 10 авг. 2026
Источник: nvd
CVSS3: 8.4
CVSS3: 9.9
EPSS Низкий

Описание

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the block_rem variable, occurs when a user opens a specially crafted .psd image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gimp:gimp:3.3.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00308
Низкий

8.4 High

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-191

Связанные уязвимости

CVSS3: 8.4
ubuntu
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

CVSS3: 8.4
redhat
2 месяца назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

CVSS3: 8.4
debian
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, ...

CVSS3: 8.4
github
17 дней назад

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system.

EPSS

Процентиль: 24%
0.00308
Низкий

8.4 High

CVSS3

9.9 Critical

CVSS3

Дефекты

CWE-191