Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

github логотип

GHSA-p2xc-g3qc-p2mq

около 2 месяцев назад

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-66758

около 2 месяцев назад

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-66758

2 месяца назад

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-66758

около 2 месяцев назад

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-66758

около 2 месяцев назад

A flaw was found in the file-fits plugin in GIMP. When processing a FI ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21521-1

около 2 месяцев назад

Security update for gimp

EPSS: Низкий
oracle-oval логотип

ELSA-2026-50817

около 1 месяца назад

ELSA-2026-50817: gimp security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:62507

16 дней назад

Important: gimp:2.8 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-62507-0

16 дней назад

ELSA-2026-62507-0: gimp:2.8 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-p2xc-g3qc-p2mq

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-66758

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-66758

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-66758

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-66758

A flaw was found in the file-fits plugin in GIMP. When processing a FI ...

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21521-1

Security update for gimp

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-50817

ELSA-2026-50817: gimp security update (IMPORTANT)

около 1 месяца назад
rocky логотип
RLSA-2026:62507

Important: gimp:2.8 security update

16 дней назад
oracle-oval логотип
ELSA-2026-62507-0

ELSA-2026-62507-0: gimp:2.8 security update (IMPORTANT)

16 дней назад

Уязвимостей на страницу