Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jul 10, 2007 |
| Gentoo Linux | — | Upgrade media-gfx/gimp. | Oct 30, 2017 | Jul 10, 2007 |
| Oracle_linux | — | Upgrade gimp-develUpgrade gimpUpgrade gimp-libs | Oct 16, 2024 | Jul 10, 2007 |
| Suse | — | Upgrade gimpUpgrade gimp-unstable-develUpgrade suse-releaseUpgrade gimp-unstableUpgrade gimp-devel | Dec 12, 2013 | Jul 10, 2007 |
| Ubuntu | — | Upgrade gimp | Nov 8, 2024 | Jul 10, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub