Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6384

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's ReadJeffsImage function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.

Отчет

Important: This flaw in GIMP's GIF image processing component allows an attacker to trigger a buffer overflow by providing a specially crafted GIF file. This could lead to a denial of service or arbitrary code execution. Exploitation requires user interaction to open a malicious GIF file.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpWill not fix
Red Hat Enterprise Linux 7gimpNot affected
Red Hat Enterprise Linux 8gimp:2.8/gimpWill not fix
Red Hat Enterprise Linux 9gimpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2458749gimp: GIMP: Arbitrary code execution or denial of service via buffer overflow in GIF image processing

EPSS

Процентиль: 18%
0.00261
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
5 месяцев назад

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.

CVSS3: 7.3
nvd
5 месяцев назад

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.

CVSS3: 7.3
debian
5 месяцев назад

A flaw was found in gimp. This buffer overflow vulnerability in the GI ...

CVSS3: 7.8
redos
около 2 месяцев назад

Уязвимость gimp

CVSS3: 7.3
github
5 месяцев назад

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.

EPSS

Процентиль: 18%
0.00261
Низкий

7.3 High

CVSS3

Уязвимость CVE-2026-6384