Описание
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of DDS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
. Was ZDI-CAN-22093.
A parsing vulnerability was found in the GNU Image Manipulation Program (GIMP). This flaw allows an unauthenticated, remote attacker to trick a GIMP user into opening a malicious DDS file, possibly enabling the execution of unauthorized code within the GIMP process.
Отчет
Red Hat Enterprise Linux 7 and 8 is not affected by this issue as the DDS plugin was added in gimp 2.10.10.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | gimp | Not affected | ||
Red Hat Enterprise Linux 7 | gimp | Not affected | ||
Red Hat Enterprise Linux 8 | gimp | Not affected | ||
Red Hat Enterprise Linux 9 | gimp | Fixed | RHSA-2024:0675 | 05.02.2024 |
Red Hat Enterprise Linux 9 | gimp | Fixed | RHSA-2025:3617 | 07.04.2025 |
Red Hat Enterprise Linux 9 | gimp | Fixed | RHSA-2025:7417 | 13.05.2025 |
Red Hat Enterprise Linux 9.0 Extended Update Support | gimp | Fixed | RHSA-2024:0716 | 07.02.2024 |
Red Hat Enterprise Linux 9.2 Extended Update Support | gimp | Fixed | RHSA-2024:0702 | 06.02.2024 |
Red Hat Enterprise Linux 9.4 Extended Update Support | gimp | Fixed | RHSA-2025:3629 | 07.04.2025 |
Показывать по
Дополнительная информация
Статус:
7.8 High
CVSS3
Связанные уязвимости
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DDS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22093.
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DDS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-22093.
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution ...
GIMP DDS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DDS files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22093.
7.8 High
CVSS3