Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-48798

Опубликовано: 26 мая 2025
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

Отчет

This vulnerability in GIMP's XCF parser marked as Important rather than Moderate due to the nature and impact of the underlying memory management flaws—specifically, use-after-free and double-free conditions. These are not just stability issues; they are well-known, high-severity primitives that attackers often exploit to achieve arbitrary code execution. Given that GIMP is a widely used graphics application and image files are routinely exchanged, the attack vector is easily accessible and plausible through social engineering (e.g., email attachments or file downloads). Furthermore, such vulnerabilities occur during file parsing—a stage often executed automatically upon file open—minimizing user interaction and maximizing the risk.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7gimpAffected
Red Hat Enterprise Linux 8gimpFixedRHSA-2025:916517.06.2025
Red Hat Enterprise Linux 9gimpFixedRHSA-2025:916217.06.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2368557gimp: Multiple use after free in XCF parser

EPSS

Процентиль: 2%
0.00014
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
22 дня назад

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

CVSS3: 7.3
nvd
22 дня назад

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

CVSS3: 7.3
debian
22 дня назад

A flaw was found in GIMP when processing XCF image files. If a user op ...

CVSS3: 7.3
github
22 дня назад

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

EPSS

Процентиль: 2%
0.00014
Низкий

7.3 High

CVSS3

Уязвимость CVE-2025-48798