Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58383

Опубликовано: 11 апр. 2026
Источник: redhat
CVSS3: 7.3

Описание

A flaw was found in GIMP's Jeff's Image Format (JIF) parser. A heap-based out-of-bounds write occurs in the ReadJeffsImage() function when a crafted JIF file sets bits-per-pixel to 0, causing the unpack loop to never advance and to write indefinitely past the destination buffer. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

Отчет

A flaw was found in GIMP's Jeff's Image Format (JIF) parser. When a crafted JIF file sets bits-per-pixel to 0, the unpack loop in ReadJeffsImage() never advances and writes past the destination buffer, leading to memory corruption. Successful exploitation requires a user to open a specially crafted JIF file in a build that includes the JIF import path.

Меры по смягчению последствий

None — requires opening a crafted JIF/GIF file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpNot affected
Red Hat Enterprise Linux 7gimpNot affected
Red Hat Enterprise Linux 8gimp:2.8/gimpNot affected
Red Hat Enterprise Linux 9gimpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2497430gimp: gimp: Heap buffer overflow via bpp=0 infinite loop in ReadJeffsImage()

7.3 High

CVSS3

Связанные уязвимости

ubuntu
26 дней назад

[Unknown description]

debian

Описание отсутствует

7.3 High

CVSS3