Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-48798

Опубликовано: 26 мая 2025
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

Отчет

This vulnerability in GIMP's XCF parser marked as Important rather than Moderate due to the nature and impact of the underlying memory management flaws—specifically, use-after-free and double-free conditions. These are not just stability issues; they are well-known, high-severity primitives that attackers often exploit to achieve arbitrary code execution. Given that GIMP is a widely used graphics application and image files are routinely exchanged, the attack vector is easily accessible and plausible through social engineering (e.g., email attachments or file downloads). Furthermore, such vulnerabilities occur during file parsing—a stage often executed automatically upon file open—minimizing user interaction and maximizing the risk.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle SupportgimpFixedRHSA-2025:950124.06.2025
Red Hat Enterprise Linux 8gimpFixedRHSA-2025:916517.06.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportgimpFixedRHSA-2025:931023.06.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgimpFixedRHSA-2025:930823.06.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportgimpFixedRHSA-2025:930923.06.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicegimpFixedRHSA-2025:930923.06.2025
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsgimpFixedRHSA-2025:930923.06.2025
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicegimpFixedRHSA-2025:956924.06.2025
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsgimpFixedRHSA-2025:956924.06.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2368557gimp: Multiple use after free in XCF parser

EPSS

Процентиль: 3%
0.00017
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
2 месяца назад

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

CVSS3: 7.3
nvd
2 месяца назад

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

CVSS3: 7.3
debian
2 месяца назад

A flaw was found in GIMP when processing XCF image files. If a user op ...

CVSS3: 7.3
github
2 месяца назад

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

suse-cvrf
около 1 месяца назад

Security update for gimp

EPSS

Процентиль: 3%
0.00017
Низкий

7.3 High

CVSS3