Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-10921

Опубликовано: 29 окт. 2025
Источник: redhat
CVSS3: 7.8

Описание

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27803.

A heap-based buffer-overflow in GIMP’s HDR (RGBE) file parsing (CVE-2025-10921 / ZDI-25-910) allows an attacker to execute arbitrary code when a user opens or is tricked into previewing a malicious HDR file. The flaw is caused by missing length validation before copying user-supplied HDR data into a heap buffer, enabling memory corruption and control of program flow.

Отчет

This vulnerability is Important because it enables remote code execution in the context of the user’s GIMP process with relatively low prerequisites: an attacker only needs to supply a crafted HDR file and get the victim to open or preview it. Heap overflows in image-parsing code are especially dangerous because image loaders commonly operate on untrusted files and often run in the same process as the application’s UI and plugins; a successful overwrite of heap metadata or adjacent control data can lead to arbitrary instruction-pointer control (RCE). Although exploitation requires user interaction (opening/preview), the attack surface is large (attachments, downloads, web previews) and the payload can execute with the user’s privileges, potentially leading to system compromise or lateral movement if the user has elevated access.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7gimpNot affected
Red Hat Enterprise Linux 8gimpFixedRHSA-2025:2241701.12.2025
Red Hat Enterprise Linux 9gimpFixedRHSA-2025:2196824.11.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2407194gimp: GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
5 месяцев назад

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27803.

CVSS3: 7.8
nvd
5 месяцев назад

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27803.

CVSS3: 7.8
debian
5 месяцев назад

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution ...

suse-cvrf
4 месяца назад

Security update for gegl

suse-cvrf
4 месяца назад

Security update for gegl

7.8 High

CVSS3