Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-48797

Опубликовано: 26 мая 2025
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

Меры по смягчению последствий

Currently no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle SupportgimpFixedRHSA-2025:950124.06.2025
Red Hat Enterprise Linux 8gimpFixedRHSA-2025:916517.06.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportgimpFixedRHSA-2025:931023.06.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgimpFixedRHSA-2025:930823.06.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportgimpFixedRHSA-2025:930923.06.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicegimpFixedRHSA-2025:930923.06.2025
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsgimpFixedRHSA-2025:930923.06.2025
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicegimpFixedRHSA-2025:956924.06.2025
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsgimpFixedRHSA-2025:956924.06.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2368558gimp: Multiple heap buffer overflows in TGA parser

EPSS

Процентиль: 2%
0.00017
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
2 месяца назад

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

CVSS3: 7.3
nvd
2 месяца назад

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

CVSS3: 7.3
debian
2 месяца назад

A flaw was found in GIMP when processing certain TGA image files. If a ...

CVSS3: 7.3
github
2 месяца назад

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

suse-cvrf
около 1 месяца назад

Security update for gimp

EPSS

Процентиль: 2%
0.00017
Низкий

7.3 High

CVSS3