Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gimp | Jul 30, 2024 | Jun 8, 2007 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 7, 2022 |
| Suse | — | Upgrade gimp-debugsourceUpgrade libgimp-2_0-0-32bitUpgrade libgimpui-2_0-0-debuginfoUpgrade libgimp-2_0-0-debuginfoUpgrade libgimpui-2_0-0-32bitUpgrade gimp-help-browserUpgrade gimp-develUpgrade gimp-help-browser-debuginfoUpgrade gimp-langUpgrade libgimp-2_0-0-debuginfo-32bitUpgrade libgimpui-2_0-0Upgrade libgimp-2_0-0Upgrade gimp-plugin-aaUpgrade gimp-plugins-python-debuginfoUpgrade gimp-devel-debuginfoUpgrade gimp-debuginfoUpgrade libgimpui-2_0-0-debuginfo-32bitUpgrade gimpUpgrade gimp-plugins-pythonUpgrade gimp-plugin-aa-debuginfo | Apr 26, 2018 | Jun 7, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub