Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6695

Опубликовано: 20 апр. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.

Отчет

An Important heap-based out-of-bounds write vulnerability exists in the PAA file format plugin of GIMP. This flaw allows an attacker to achieve potential remote code execution by tricking a user into opening a specially crafted .paa file. Red Hat Enterprise Linux systems where GIMP is installed and used to process untrusted image files are affected.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening .paa files from untrusted sources. If GIMP is not required, consider removing the gimp package to eliminate the attack vector. Removing the gimp package may also remove other desktop-related packages that depend on it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gimpFix deferred
Red Hat Enterprise Linux 7gimpFix deferred
Red Hat Enterprise Linux 8gimp:2.8/gimpFix deferred
Red Hat Enterprise Linux 9gimpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2459780gimp: GIMP: Remote Code Execution via crafted PAA file

EPSS

Процентиль: 5%
0.00152
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 дня назад

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.

CVSS3: 5.5
nvd
4 дня назад

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.

CVSS3: 5.5
debian
4 дня назад

A flaw was found in GIMP. A remote attacker could exploit this by tric ...

CVSS3: 5.5
github
4 дня назад

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system.

EPSS

Процентиль: 5%
0.00152
Низкий

5.5 Medium

CVSS3