Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40919

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in GIMP. This vulnerability, a buffer overflow in the file-seattle-filmworks plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potentially impacting the stability of the GIMP application.

Отчет

This Moderate impact flaw in GIMP's file-seattle-filmworks plugin can lead to a denial of service. Exploitation requires a user to open a specially crafted Seattle Filmworks file. This could cause the GIMP application to crash, affecting its stability.

Меры по смягчению последствий

To mitigate this vulnerability, users should exercise caution and avoid opening untrusted Seattle Filmworks (.sfw) files with GIMP. Processing untrusted files can trigger the buffer overflow, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpFix deferred
Red Hat Enterprise Linux 7gimpFix deferred
Red Hat Enterprise Linux 8gimp:2.8/gimpFix deferred
Red Hat Enterprise Linux 9gimpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2458748gimp: GIMP: Denial of Service via specially crafted Seattle Filmworks file

EPSS

Процентиль: 25%
0.00331
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
4 месяца назад

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potentially impacting the stability of the GIMP application.

CVSS3: 6.1
nvd
4 месяца назад

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potentially impacting the stability of the GIMP application.

CVSS3: 6.1
debian
4 месяца назад

A flaw was found in GIMP. This vulnerability, a buffer overflow in the ...

CVSS3: 6.1
github
4 месяца назад

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potentially impacting the stability of the GIMP application.

CVSS3: 6.1
fstec
4 месяца назад

Уязвимость плагина file-seattle-filmworks библиотеки для обработки изображений Gimp, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 25%
0.00331
Низкий

6.1 Medium

CVSS3