Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jun 8, 2007 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 7, 2022 |
| Suse | — | Upgrade gimp-langUpgrade gimp-develUpgrade gimp-plugins-pythonUpgrade gimp-plugin-aaUpgrade gimpUpgrade libgimpui-2_0-0Upgrade libgimp-2_0-0 | Apr 26, 2018 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub